CVE Vulnerabilities

CVE-2024-39839

Published: Aug 01, 2024 | Modified: Sep 04, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadnt been synced before.

Affected Software

Name Vendor Start Version End Version
Mattermost_server Mattermost 9.5.0 (including) 9.5.7 (excluding)
Mattermost_server Mattermost 9.7.0 (including) 9.7.6 (excluding)
Mattermost_server Mattermost 9.8.0 (including) 9.8.2 (excluding)
Mattermost_server Mattermost 9.9.0 (including) 9.9.0 (including)

References