Lack of permission check when updating the profile picture of a remote user (shared channels enabled)
8Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 2.7epss 0.3%
probabilidade de exploração
0.3%top 77% das CVEs
exploração observada
nãonenhuma fonte reporta
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Produtos afetados
Mattermost · MattermostReferências
https://mattermost.com/security-updates