Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-36003 Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.
Fixes

Solution

Update Mattermost to versions 9.9.0, 9.8.1, 9.5.6 or higher.


Workaround

No workaround given by the vendor.

References
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-02T03:37:03.658Z

Reserved: 2024-07-01T10:22:11.588Z

Link: CVE-2024-36257

cve-icon Vulnrichment

Updated: 2024-08-02T03:37:03.658Z

cve-icon NVD

Status : Modified

Published: 2024-07-03T09:15:06.247

Modified: 2024-11-21T09:21:56.843

Link: CVE-2024-36257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses