PT-2024-28692 · Mattermost · Mattermost

Juho Forsén

·

Published

2024-08-01

·

Updated

2024-09-05

·

CVE-2024-39837

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.9.x through 9.9.0 Mattermost versions 9.5.x through 9.5.6
Description The issue is related to the improper restriction of channel creation, allowing a malicious remote user to create arbitrary channels when shared channels are enabled. This is due to a failure in properly restricting channel creation.
Recommendations For Mattermost versions 9.9.x through 9.9.0, update to a version that properly restricts channel creation. For Mattermost versions 9.5.x through 9.5.6, update to a version that properly restricts channel creation. As a temporary workaround, consider disabling shared channels to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-39837
CVE-2024-39837
GHSA-VVPG-55P7-5H8W
GO-2024-3032

Affected Products

Mattermost