CVE-2024-39836
22.08.2024, 07:15
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allowsthe munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, whenthey are valid, functional emails.Enginsight
Vendor | Product | Version |
---|---|---|
mattermost | mattermost | 9.5.0 ≤ 𝑥 < 9.5.8 |
mattermost | mattermost | 9.8.0 ≤ 𝑥 < 9.8.3 |
mattermost | mattermost | 9.9.0 ≤ 𝑥 < 9.9.2 |
mattermost | mattermost | 9.10.0 ≤ 𝑥 < 9.10.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References