← Voltar para CVEs
CVE-2024-36257
LOW2.7
Descricao
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.
Detalhes CVE
Pontuacao CVSS v3.12.7
SeveridadeLOW
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosHIGH
Interacao do usuarioNONE
Publicado7/3/2024
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
mattermost:mattermost
Fraquezas (CWE)
CWE-284
Referencias
https://mattermost.com/security-updates(responsibledisclosure@mattermost.com)
https://mattermost.com/security-updates(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.