PT-2024-37620 · Mattermost · Mattermost

Juho Forsén

·

Published

2024-07-03

·

Updated

2024-07-05

·

CVE-2024-6428

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.5.x through 9.5.5 Mattermost versions 9.6.x through 9.6.2 Mattermost versions 9.7.x through 9.7.4 Mattermost version 9.8.0
Description The issue allows an attacker to specify both a remoteId and the user ID when creating a new user, resulting in a user with a user-defined user ID. This can cause broken functionality in User Management, such as administrative actions against the user not working.
Recommendations For Mattermost versions 9.5.x through 9.5.5, update to a version that prevents specifying a RemoteId when creating a new user. For Mattermost versions 9.6.x through 9.6.2, update to a version that prevents specifying a RemoteId when creating a new user. For Mattermost versions 9.7.x through 9.7.4, update to a version that prevents specifying a RemoteId when creating a new user. For Mattermost version 9.8.0, update to a version that prevents specifying a RemoteId when creating a new user.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-6428

Affected Products

Mattermost