Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using...
Low severity
Unreviewed
Published
Jul 3, 2024
to the GitHub Advisory Database
•
Updated Jul 3, 2024
Description
Published by the National Vulnerability Database
Jul 3, 2024
Published to the GitHub Advisory Database
Jul 3, 2024
Last updated
Jul 3, 2024
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.
References