CVE-2024-6428: Limited DoS due to permitting creating users with user-defined IDs
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause some broken functionality in User Management such administrative actions against the user not working.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.9.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.8.1 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.7.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.6.3 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.5.6
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6428?
CVE-2024-6428 has been classified as a high severity vulnerability due to its potential to allow unauthorized user creation.
How do I fix CVE-2024-6428?
To fix CVE-2024-6428, upgrade to Mattermost versions 9.8.1, 9.7.5, 9.6.3, or 9.5.6 or later.
What versions of Mattermost are affected by CVE-2024-6428?
CVE-2024-6428 affects Mattermost versions 9.8.0, 9.7.0 to 9.7.4, 9.6.0 to 9.6.2, and 9.5.0 to 9.5.5.
What is the impact of CVE-2024-6428?
The impact of CVE-2024-6428 includes the ability for attackers to create users with arbitrary user IDs.
Is CVE-2024-6428 a remote vulnerability?
Yes, CVE-2024-6428 is a remote vulnerability that can be exploited without physical access to the server.