PT-2024-28688 · Mattermost · Mattermost

·

CVE-2024-39830

·

Published

2024-07-03

·

Updated

2024-07-05

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.5.x through 9.5.5 Mattermost versions 9.6.x through 9.6.2 Mattermost versions 9.7.x through 9.7.4 Mattermost versions 9.8.x through 9.8.0
Description The issue arises when shared channels are enabled, and the software fails to use constant time comparison for remote cluster tokens. This allows an attacker to potentially retrieve the remote cluster token via a timing attack during remote cluster token comparison.
Recommendations For Mattermost versions 9.5.x through 9.5.5, update to a version that uses constant time comparison for remote cluster tokens. For Mattermost versions 9.6.x through 9.6.2, update to a version that uses constant time comparison for remote cluster tokens. For Mattermost versions 9.7.x through 9.7.4, update to a version that uses constant time comparison for remote cluster tokens. For Mattermost versions 9.8.x through 9.8.0, update to a version that uses constant time comparison for remote cluster tokens.

Exploit

Fix

Side Channel Attack

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-39830

Affected Products

Mattermost