HIGH 8.7 Go
Mattermost allows unsolicited invites to expose access to local channels
GHSA-q22q-2rrf-m27p · CVE-2024-39777 · GO-2024-3092
Published · Modified
Description
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local channel, and that local channel will then become shared without the consent of the local admin.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes