CVE-2024-41162: Malicious remote can make an arbitrary local channel read-only
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41162?
CVE-2024-41162 is classified as a moderate severity vulnerability due to the potential for unauthorized modification of local channels.
How do I fix CVE-2024-41162?
To fix CVE-2024-41162, you should upgrade to Mattermost version 9.9.1 or later, or apply the appropriate patch for your affected version.
Which Mattermost versions are affected by CVE-2024-41162?
CVE-2024-41162 affects Mattermost versions 9.9.0, 9.5.6, 9.7.5, and 9.8.1 and earlier.
What kind of attack can be executed due to CVE-2024-41162?
CVE-2024-41162 allows a malicious remote user to make arbitrary local channels read-only, which could lead to disruption of communications.
Is there a workaround for CVE-2024-41162 if I cannot update immediately?
There is no specific workaround for CVE-2024-41162; the recommended action is to apply the necessary update as soon as possible.