PT-2024-28690 · Mattermost · Mattermost

Juho Forsén

·

Published

2024-08-01

·

Updated

2024-08-23

·

CVE-2024-39832

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.5.x through 9.5.6 Mattermost versions 9.7.x through 9.7.5 Mattermost versions 9.8.x through 9.8.1 Mattermost versions 9.9.x through 9.9.0
Description The issue arises from improper error handling, allowing a malicious remote actor to permanently delete local data by exploiting this weakness when share channels are enabled. This can be achieved by abusing dangerous error handling in the mattermost-server.
Recommendations For Mattermost versions 9.5.x through 9.5.6, update to a version later than 9.5.6 to resolve the issue. For Mattermost versions 9.7.x through 9.7.5, update to a version later than 9.7.5 to resolve the issue. For Mattermost versions 9.8.x through 9.8.1, update to a version later than 9.8.1 to resolve the issue. For Mattermost versions 9.9.x through 9.9.0, update to a version later than 9.9.0 to resolve the issue. As a temporary workaround, consider disabling share channels to minimize the risk of exploitation.

Fix

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-39832
GHSA-762M-4CX6-6MF4
GO-2024-3020

Affected Products

Mattermost