TROYANOSYVIRUS
Retour aux CVEs

CVE-2024-39836

MEDIUM
4.8

Description

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails.

Details CVE

Score CVSS v3.14.8
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteHIGH
Privileges requisNONE
Interaction utilisateurNONE
Publie8/22/2024
Derniere modification8/23/2024
Sourcenvd
Observations honeypot0

Produits affectes

mattermost:mattermost

Faiblesses (CWE)

CWE-693

References

https://mattermost.com/security-updates(responsibledisclosure@mattermost.com)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.