CVE-2024-39836: Munged email address used for password resets and notifications
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39836?
CVE-2024-39836 is considered a high-severity vulnerability due to the potential exploitation involving unauthorized session creation and password resets.
How do I fix CVE-2024-39836?
To fix CVE-2024-39836, update your Mattermost installation to version 9.5.8, 9.8.3, 9.9.2, or 9.10.1 or later.
Which versions of Mattermost are affected by CVE-2024-39836?
Mattermost versions 9.9.x up to 9.9.1, 9.5.x up to 9.5.7, 9.10.x up to 9.10.0, and 9.8.x up to 9.8.2 are affected by CVE-2024-39836.
What type of vulnerability is CVE-2024-39836?
CVE-2024-39836 is classified as an access control vulnerability that allows unauthorized users to potentially create sessions and reset passwords.
How can I check if my Mattermost version is affected by CVE-2024-39836?
You can check if your Mattermost version is affected by comparing your current version against the listed vulnerable versions in CVE-2024-39836.