First published: Fri Apr 05 2024(Updated: )
Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/mattermost/mattermost/server/v8 | >=9.3.0<9.3.3 | 9.3.3 |
go/github.com/mattermost/mattermost/server/v8 | >=9.4.0<9.4.4 | 9.4.4 |
go/github.com/mattermost/mattermost/server/v8 | >=9.5.0<9.5.2 | 9.5.2 |
go/github.com/mattermost/mattermost/server/v8 | >=8.1.0<8.1.11 | 8.1.11 |
Mattermost | >=8.1.0<8.1.11 | |
Mattermost | >=9.3.0<9.3.3 | |
Mattermost | >=9.4.0<9.4.4 | |
Mattermost | >=9.5.0<9.5.2 |
Update Mattermost Server to versions 9.6.0, 9.5.2, 9.4.4, 9.3.3, 8.1.11 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2447 is rated as a moderate severity vulnerability due to the potential for authenticated users to impersonate other users.
To fix CVE-2024-2447, you should upgrade Mattermost Server to version 8.1.11, 9.3.3, 9.4.4, or 9.5.2.
CVE-2024-2447 affects Mattermost versions 8.1.x prior to 8.1.11, 9.3.x prior to 9.3.3, 9.4.x prior to 9.4.4, and 9.5.x prior to 9.5.2.
CVE-2024-2447 requires authentication to exploit, as it involves actions taken by authenticated users.
CVE-2024-2447 enables an authenticated attacker to create posts as other users via crafted post actions.