VYPR
Low severityNVD Advisory· Published Aug 1, 2024· Updated Aug 1, 2024

Malicious remote can create arbitrary channels

CVE-2024-39837

Description

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost/server/v8Go
>= 9.5.0, < 9.5.79.5.7
github.com/mattermost/mattermost/server/v8Go
>= 9.9.0, < 9.9.19.9.1
github.com/mattermost/mattermost/server/v8Go
< 8.0.0-20240626164322-c758cecaf30c8.0.0-20240626164322-c758cecaf30c
github.com/mattermost/mattermost-serverGo
>= 9.9.0, < 9.9.19.9.1
github.com/mattermost/mattermost-server/v5Go
< 5.3.2-0.20240626164322-c758cecaf30c5.3.2-0.20240626164322-c758cecaf30c
github.com/mattermost/mattermost-server/v6Go
< 6.0.0-20240626164322-c758cecaf30c6.0.0-20240626164322-c758cecaf30c
github.com/mattermost/mattermost-serverGo
>= 9.5.0, < 9.5.79.5.7

Affected products

1

Patches

1

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

4

News mentions

0

No linked articles in our index yet.