CVE-2024-32939: Email addresses of remote users visible in props regardless of server settings
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32939?
CVE-2024-32939 has been classified as a vulnerability that could lead to potential information disclosure.
How do I fix CVE-2024-32939?
To fix CVE-2024-32939, update Mattermost to version 9.5.8, 9.9.2, 9.10.1, or 9.8.3 or a later version.
Which versions of Mattermost are affected by CVE-2024-32939?
Mattermost versions 9.5.0 to 9.5.7, 9.8.0 to 9.8.2, 9.9.0 to 9.9.1, and 9.10.0 are affected by CVE-2024-32939.
What type of vulnerability is CVE-2024-32939?
CVE-2024-32939 is classified as an information disclosure vulnerability affecting shared channels in Mattermost.
What should I do if I cannot update to the fixed versions for CVE-2024-32939?
If you cannot update, consider implementing access controls or disabling shared channels to mitigate the risk associated with CVE-2024-32939.