
CVE-2024-43813 – IDOR when marking read a user's channel
https://notcve.org/view.php?id=CVE-2024-43813
22 Aug 2024 — Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any user. Las versiones 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 de Mattermost no aplican controles de acceso adecuados que permiten a cualquier usuario autenticado, incluidos los invitados, marcar cualquier canal dentro de cualquier equipo como leído para cualquier usuario. Mattermost versions 9.5.x <= 9.5.7, 9.10.x ... • https://mattermost.com/security-updates • CWE-284: Improper Access Control •

CVE-2024-39810 – Server crash via Elasticsearch certificate file
https://notcve.org/view.php?id=CVE-2024-39810
22 Aug 2024 — Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path field, such as /dev/zero and, after testing the connection, cause the application to crash. Las versiones 9.5.x <= 9.5.7 y 9.10.x <= 9.10.0 de Mattermost no limitan el tiempo ni el tamaño del archivo de ruta de CA en la configuración de ElasticSearch, lo que p... • https://mattermost.com/security-updates • CWE-400: Uncontrolled Resource Consumption •

CVE-2024-32939 – Email addresses of remote users visible in props regardless of server settings
https://notcve.org/view.php?id=CVE-2024-32939
22 Aug 2024 — Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server." Las versiones de Mattermost 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, cuando los canales compartidos están habilitados, no se pueden redactar las direcciones de correo electrónico originales de l... • https://mattermost.com/security-updates • CWE-284: Improper Access Control •

CVE-2024-39836 – Munged email address used for password resets and notifications
https://notcve.org/view.php?id=CVE-2024-39836
22 Aug 2024 — Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails. Las versiones de Mattermost 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 y 9.8.x <= 9.8.2 no garantizan que los usuarios remotos/sintéticos no pued... • https://mattermost.com/security-updates • CWE-693: Protection Mechanism Failure •

CVE-2024-41926 – Malicious remote can claim that a user was synced from another remote
https://notcve.org/view.php?id=CVE-2024-41926
01 Aug 2024 — Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote. Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and ther... • https://mattermost.com/security-updates • CWE-284: Improper Access Control •

CVE-2024-41162 – Malicious remote can make an arbitrary local channel read-only
https://notcve.org/view.php?id=CVE-2024-41162
01 Aug 2024 — Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only. Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local chann... • https://mattermost.com/security-updates • CWE-284: Improper Access Control •

CVE-2024-41144 – Malicious remote can create/update/delete arbitrary posts in arbitrary channels
https://notcve.org/view.php?id=CVE-2024-41144
01 Aug 2024 — Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled, which allows a malicious remote to create/update/delete arbitrary posts in arbitrary channels Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled, which allows a malicious remote to create/update/delete arbitrary posts in arbitrary channels • https://mattermost.com/security-updates • CWE-284: Improper Access Control •

CVE-2024-39839 – Remote username set to an arbitrary string by remote user
https://notcve.org/view.php?id=CVE-2024-39839
01 Aug 2024 — Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadn't been synced before. Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared c... • https://mattermost.com/security-updates • CWE-284: Improper Access Control •

CVE-2024-39837 – Malicious remote can create arbitrary channels
https://notcve.org/view.php?id=CVE-2024-39837
01 Aug 2024 — Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled. Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled. • https://mattermost.com/security-updates • CWE-284: Improper Access Control •

CVE-2024-39832 – Permanently local data deletion by malicious remote
https://notcve.org/view.php?id=CVE-2024-39832
01 Aug 2024 — Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled. • https://mattermost.com/security-updates • CWE-754: Improper Check for Unusual or Exceptional Conditions •