CVE-2024-36255: Post actions can run playbook checklist task commands
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post action that unexpectedly runs a slash command in some arbitrary channel.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36255?
The severity of CVE-2024-36255 is high due to improper input validation that allows for unauthorized command execution.
How do I fix CVE-2024-36255?
To fix CVE-2024-36255, upgrade Mattermost to version 9.5.4, 9.6.2, or 8.1.13 or later.
What versions of Mattermost are affected by CVE-2024-36255?
Mattermost versions 9.5.x up to 9.5.3, 9.6.x up to 9.6.1, and 8.1.x up to 8.1.12 are affected by CVE-2024-36255.
Can CVE-2024-36255 be exploited remotely?
Yes, CVE-2024-36255 can be exploited remotely as it involves the execution of commands through deceptive post actions.
What are the potential impacts of CVE-2024-36255?
The potential impacts of CVE-2024-36255 include unauthorized access and execution of commands impersonating other users.