CVE-2024-40886: One-click Client-Side Path Traversal Leading to CSRF in User Management admin page
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in User Management page of the system console.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40886?
CVE-2024-40886 has been classified as a medium severity vulnerability due to its potential for client-side path traversal leading to CSRF.
How do I fix CVE-2024-40886?
To address CVE-2024-40886, upgrade to Mattermost version 9.5.8, 9.8.3, 9.9.2, or 9.10.1.
Which versions of Mattermost are affected by CVE-2024-40886?
Mattermost versions 9.9.x up to 9.9.1, 9.5.x up to 9.5.7, 9.10.x up to 9.10.0, and 9.8.x up to 9.8.2 are affected by CVE-2024-40886.
What type of vulnerability is CVE-2024-40886?
CVE-2024-40886 is a client-side path traversal vulnerability that can lead to cross-site request forgery (CSRF).
What components are involved in CVE-2024-40886?
CVE-2024-40886 involves user input sanitization failures in the frontend of the Mattermost application.