CVE-2024-39832: Permanently local data deletion by malicious remote
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39832?
CVE-2024-39832 has a severe impact as it allows a malicious remote user to permanently delete local data.
How do I fix CVE-2024-39832?
To fix CVE-2024-39832, update Mattermost to version 9.9.1, 9.8.2, 9.7.6, or 9.5.7 depending on your current version.
Which versions of Mattermost are affected by CVE-2024-39832?
Mattermost versions 9.9.x up to 9.9.0, 9.5.x up to 9.5.6, 9.7.x up to 9.7.5, and 9.8.x up to 9.8.1 are affected by CVE-2024-39832.
What kind of attack does CVE-2024-39832 enable?
CVE-2024-39832 enables attackers to abuse improper error handling, allowing them to delete local data when share channels are enabled.
Is CVE-2024-39832 present in previous Mattermost releases?
Yes, CVE-2024-39832 exists in earlier releases of Mattermost prior to the recommended patched versions.