PT-2024-28694 · Mattermost · Mattermost

Juho Forsén

·

Published

2024-08-01

·

Updated

2024-09-05

·

CVE-2024-39839

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.5.x through 9.5.6 Mattermost versions 9.7.x through 9.7.5 Mattermost versions 9.8.x through 9.8.1 Mattermost versions 9.9.x through 9.9.0
Description The issue allows a user on a remote server to set their remote username property to an arbitrary string when shared channels are enabled. This arbitrary string would then be synced to the local server if the user hadn't been synced before.
Recommendations For Mattermost versions 9.5.x through 9.5.6, update to a version that disallows users from setting their own remote username. For Mattermost versions 9.7.x through 9.7.5, update to a version that disallows users from setting their own remote username. For Mattermost versions 9.8.x through 9.8.1, update to a version that disallows users from setting their own remote username. For Mattermost versions 9.9.x through 9.9.0, update to a version that disallows users from setting their own remote username. As a temporary workaround, consider restricting the ability of users to set their remote username property until a patch is available.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-39839
CVE-2024-39839
GHSA-VG6Q-84P8-QVQH
GO-2024-3024

Affected Products

Mattermost