CVE-2024-39839: Remote username set to an arbitrary string by remote user
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadn't been synced before.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39839?
CVE-2024-39839 has a moderate severity level due to the potential for unauthorized users to set arbitrary remote usernames.
How do I fix CVE-2024-39839?
To fix CVE-2024-39839, update Mattermost to version 9.9.1, 9.8.2, 9.7.6, or 9.5.7 or later.
Which versions are affected by CVE-2024-39839?
CVE-2024-39839 affects Mattermost versions 9.9.0, 9.5.6, 9.7.5, and 9.8.1 and earlier.
What is the impact of CVE-2024-39839?
The impact of CVE-2024-39839 allows users to set arbitrary remote usernames in shared channels, leading to potential impersonation.
Is there a workaround for CVE-2024-39839?
There are no official workarounds for CVE-2024-39839, thus updating to a patched version is the recommended approach.