CVE-2024-39836

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to  ensure that remote/synthetic users cannot create sessions or reset passwords, which allowsthe munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, whenthey are valid, functional emails.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
MattermostCNA
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
VendorProductVersion
mattermostmattermost
9.5.0 ≤
𝑥
< 9.5.8
mattermostmattermost
9.8.0 ≤
𝑥
< 9.8.3
mattermostmattermost
9.9.0 ≤
𝑥
< 9.9.2
mattermostmattermost
9.10.0 ≤
𝑥
< 9.10.1
𝑥
= Vulnerable software versions