CVE-2024-39274: Malicious remote can add users to arbitrary teams and channels
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the sync message is a shared channel, when shared channels are enabled, which allows a malicious remote to add users to arbitrary teams and channels
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39274?
CVE-2024-39274 has a high severity rating due to the potential for remote attackers to manipulate user access to arbitrary teams.
How do I fix CVE-2024-39274?
To fix CVE-2024-39274, upgrade to Mattermost version 9.9.1, 9.8.2, 9.7.6, or 9.5.7 depending on your current version.
What versions of Mattermost are affected by CVE-2024-39274?
Mattermost versions 9.9.0, 9.5.6, 9.7.5, and 9.8.1 are affected by CVE-2024-39274.
Can CVE-2024-39274 lead to unauthorized access?
Yes, CVE-2024-39274 can allow a malicious remote user to add users to unauthorized teams, leading to potential data exposure.
What should I do if I cannot update to a fixed version for CVE-2024-39274?
If you cannot update to a fixed version for CVE-2024-39274, consider implementing additional security measures, such as restricting access to the application.