CVE-2024-39361

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jul 3, 2024
Updated: Jul 5, 2024
CWE ID 284

Summary

CVE-2024-39361 is a vulnerability affecting Mattermost versions 9.8.0, 9.7.x up to 9.7.4, 9.6.x up to 9.6.2, and 9.5.x up to 9.5.5. This issue permits users to assign a RemoteId of their choice for their posts, allowing attackers to manipulate post IDs. By creating posts with user-defined IDs, attackers can disrupt normal functionality in channels or threads, causing potential confusion and chaos. This vulnerability can lead to broken functionality in user-defined posts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share