PT-2024-29293 · Mattermost · Mattermost

Juho Forsén

·

Published

2024-08-01

·

Updated

2024-09-05

·

CVE-2024-41144

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.9.x through 9.9.0 Mattermost versions 9.5.x through 9.5.6 Mattermost versions 9.7.x through 9.7.5 Mattermost versions 9.8.x through 9.8.1
Description The issue arises from the failure to properly validate synced posts when shared channels are enabled. This allows a malicious remote actor to create, update, or delete arbitrary posts in arbitrary channels.
Recommendations For Mattermost versions 9.9.x through 9.9.0, update to a version that properly validates synced posts. For Mattermost versions 9.5.x through 9.5.6, update to a version that properly validates synced posts. For Mattermost versions 9.7.x through 9.7.5, update to a version that properly validates synced posts. For Mattermost versions 9.8.x through 9.8.1, update to a version that properly validates synced posts.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-41144
CVE-2024-41144
GHSA-VG67-CHM7-8M3J
GO-2024-3023

Affected Products

Mattermost