PT-2024-28691 · Mattermost · Mattermost

C0Rydoras

+1

·

Published

2024-08-22

·

Updated

2024-08-30

·

CVE-2024-39836

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.8.x through 9.8.2 Mattermost versions 9.9.x through 9.9.1 Mattermost versions 9.5.x through 9.5.7 Mattermost versions 9.10.x through 9.10.0
Description The issue allows remote/synthetic users to create sessions or reset passwords, which can be used to receive email notifications and reset passwords when the munged email addresses created by shared channels are valid and functional. This is due to the failure of Mattermost to ensure that remote/synthetic users cannot create sessions or reset passwords.
Recommendations For versions 9.8.x through 9.8.2, update to a version later than 9.8.2 to resolve the issue. For versions 9.9.x through 9.9.1, update to a version later than 9.9.1 to resolve the issue. For versions 9.5.x through 9.5.7, update to a version later than 9.5.7 to resolve the issue. For versions 9.10.x through 9.10.0, update to a version later than 9.10.0 to resolve the issue.

Fix

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

CVE-2024-39836
GHSA-C6VP-JJGV-38WJ
GO-2024-3096

Affected Products

Mattermost