CVE-2024-39830: Timing attack during remote cluster token comparison when shared channels are enabled
Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time comparison for remote cluster tokens which allows an attacker to retrieve the remote cluster token via a timing attack during remote cluster token comparison.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39830?
CVE-2024-39830 is classified as a high severity vulnerability due to its potential to allow attackers to exploit timing attacks to retrieve sensitive tokens.
How do I fix CVE-2024-39830?
To fix CVE-2024-39830, upgrade Mattermost to version 9.8.1 or later, or update to versions 9.7.5, 9.6.3, or 9.5.6 or later.
What versions of Mattermost are affected by CVE-2024-39830?
CVE-2024-39830 affects Mattermost versions 9.5.5 and earlier, 9.6.2 and earlier, 9.7.4 and earlier, and 9.8.0 and earlier.
What types of attacks are possible due to CVE-2024-39830?
Due to CVE-2024-39830, attackers can perform timing attacks to extract remote cluster tokens.
Are shared channels in Mattermost vulnerable due to CVE-2024-39830?
Yes, CVE-2024-39830 highlights a vulnerability in Mattermost when shared channels are enabled.