CVE-2024-39777: Malicious remote can invite itself to an arbitrary local channel
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local channel, and that local channel will then become shared without the consent of the local admin.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39777?
CVE-2024-39777 has been classified as a high severity vulnerability.
How do I fix CVE-2024-39777?
To fix CVE-2024-39777, upgrade Mattermost to version 9.9.1, 9.8.2, 9.7.6, or 9.5.7 or higher.
Which versions of Mattermost are affected by CVE-2024-39777?
CVE-2024-39777 affects Mattermost versions 9.9.x up to 9.9.0, 9.5.x up to 9.5.6, 9.7.x up to 9.7.5, and 9.8.x up to 9.8.1.
What is the impact of CVE-2024-39777?
The impact of CVE-2024-39777 allows malicious remote users to send unsolicited invites to access local channels.
Are shared channels in Mattermost vulnerable due to CVE-2024-39777?
Yes, CVE-2024-39777 exposes vulnerabilities with shared channels when unsolicited invites are allowed.