PT-2024-29301 · Mattermost · Mattermost

Juho Forsén

·

Published

2024-08-01

·

Updated

2024-09-05

·

CVE-2024-41162

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.5.x through 9.5.6 Mattermost versions 9.7.x through 9.7.5 Mattermost versions 9.8.x through 9.8.1 Mattermost versions 9.9.x through 9.9.0
Description The issue allows a malicious remote actor to make an arbitrary local channel read-only when shared channels are enabled. This occurs because the software fails to disallow the modification of local channels by a remote actor.
Recommendations For Mattermost versions 9.5.x through 9.5.6, update to a version later than 9.5.6 to resolve the issue. For Mattermost versions 9.7.x through 9.7.5, update to a version later than 9.7.5 to resolve the issue. For Mattermost versions 9.8.x through 9.8.1, update to a version later than 9.8.1 to resolve the issue. For Mattermost versions 9.9.x through 9.9.0, update to a version later than 9.9.0 to resolve the issue.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-41162
CVE-2024-41162
GHSA-JR9X-3X7M-4J75
GO-2024-3031

Affected Products

Mattermost