CVE-2024-36255
Post actions can run playbook checklist task commands
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post action that unexpectedly runs a slash command in some arbitrary channel.
Las versiones de Mattermost 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 y 8.1.x <= 8.1.12 no realizan una validación de entrada adecuada en las acciones posteriores, lo que permite a un atacante ejecutar un comando de tarea de lista de verificación del libro de jugadas como otro usuario creando y compartiendo una acción de publicación engañosa que ejecuta inesperadamente un comando de barra diagonal en algún canal arbitrario.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-05-23 CVE Reserved
- 2024-05-26 CVE Published
- 2024-05-27 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 9.5.0 <= 9.5.3 Search vendor "Mattermost" for product "Mattermost" and version " >= 9.5.0 <= 9.5.3" | en |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 9.6.0 <= 9.6.1 Search vendor "Mattermost" for product "Mattermost" and version " >= 9.6.0 <= 9.6.1" | en |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 8.1.0 <= 8.1.12 Search vendor "Mattermost" for product "Mattermost" and version " >= 8.1.0 <= 8.1.12" | en |
Affected
|