CVE-2024-36492: Existing local user overwritten by malicious remote
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing users in shared channels. which allows a malicious remote to overwrite an existing local user.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36492?
CVE-2024-36492 is classified as a high severity vulnerability due to the potential for unauthorized user modifications.
How do I fix CVE-2024-36492?
To fix CVE-2024-36492, upgrade your Mattermost installation to version 9.9.1, 9.8.2, 9.7.6, or 9.5.7.
What versions are affected by CVE-2024-36492?
CVE-2024-36492 affects Mattermost versions 9.9.0, 9.5.6, 9.7.5, and 9.8.1 and earlier.
What is the impact of CVE-2024-36492?
The impact of CVE-2024-36492 allows a malicious remote user to overwrite existing local user accounts in shared channels.
Is there a known exploit for CVE-2024-36492?
As of now, specific exploits for CVE-2024-36492 have not been publicly disclosed, but the vulnerability poses a significant risk.