Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify both a remoteId and the post ID, resulting in creating a post with a user-defined post ID. This can cause some broken functionality in the channel or thread with user-defined posts
Advisories
Source ID Title
EUVD EUVD EUVD-2024-37918 Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify both a remoteId and the post ID, resulting in creating a post with a user-defined post ID. This can cause some broken functionality in the channel or thread with user-defined posts
Fixes

Solution

Update Mattermost to versions 9.9.0, 9.8.1, 9.7.5, 9.6.3, 9.5.6 or higher.


Workaround

No workaround given by the vendor.

References
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-02T04:26:14.801Z

Reserved: 2024-07-01T10:22:11.616Z

Link: CVE-2024-39361

cve-icon Vulnrichment

Updated: 2024-08-02T04:26:14.801Z

cve-icon NVD

Status : Modified

Published: 2024-07-03T09:15:06.917

Modified: 2024-11-21T09:27:32.293

Link: CVE-2024-39361

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses