Launch Week Day 1: Announcing Security Design Review
LOW 3.8 Go

Mattermost did not properly restrict channel creation

GHSA-vvpg-55p7-5h8w · BIT-mattermost-2024-39837 · CVE-2024-39837 · GO-2024-3032

Published · Modified

Description

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.

Ready to move

Start Securing

Free, no credit card | First findings in minutes