Channel Creation Vulnerability in Mattermost by Mattermost
CVE-2024-39837
5.4MEDIUM
What is CVE-2024-39837?
Mattermost versions 9.9.x up to and including 9.9.0 and 9.5.x up to and including 9.5.6 exhibit a flaw in the management of channel permissions. This vulnerability allows an unauthorized remote attacker to create arbitrary channels when shared channels are enabled, potentially leading to information disclosure and misuse of the platform. Organizations using these versions are advised to implement immediate corrective actions by updating to the latest secure versions and reviewing their channel sharing settings.