CVE-2024-29977: Malicious remote can create arbitrary reactions on arbitrary posts
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29977?
The severity of CVE-2024-29977 is considered to be critical due to the ability for a malicious remote user to create arbitrary reactions.
How do I fix CVE-2024-29977?
To fix CVE-2024-29977, upgrade Mattermost to version 9.9.1 or 9.5.7 or later.
Which versions of Mattermost are affected by CVE-2024-29977?
Mattermost versions 9.9.x up to and including 9.9.0 and versions 9.5.x up to and including 9.5.6 are affected by CVE-2024-29977.
What is the impact of CVE-2024-29977 on Mattermost?
CVE-2024-29977 allows a remote attacker to create arbitrary reactions on arbitrary posts, potentially leading to misinformation or abuse.
Is there a workaround for CVE-2024-29977?
There is no publicly advised workaround for CVE-2024-29977; the best action is to upgrade to a patched version.