CVE-2024-36257: Lack of permission check when updating the profile picture of a remote user (shared channels enabled)
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36257?
CVE-2024-36257 has been assigned a medium severity rating due to potential unauthorized profile picture updates across remote servers.
How do I fix CVE-2024-36257?
To mitigate CVE-2024-36257, upgrade Mattermost to versions beyond 9.5.5 or 9.8.0 as soon as possible.
What versions are affected by CVE-2024-36257?
CVE-2024-36257 affects Mattermost versions 9.5.0 through 9.5.5 and version 9.8.0.
What is the impact of CVE-2024-36257 on Mattermost?
The impact of CVE-2024-36257 includes the risk of unauthorized updates to user profile pictures from connected remote servers.
Is there a workaround for CVE-2024-36257?
Currently, the best action against CVE-2024-36257 is to update to a secure version of Mattermost, as no official workaround is provided.