Loading HuntDB...

GHSA-9fpw-c9x7-cv3j

GitHub Security Advisory

Mattermost allows remote actor to set arbitrary RemoteId values for synced users

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote.

Affected Packages

Go github.com/mattermost/mattermost/server/v8
Affected versions: 9.5.0 (fixed in 9.5.7)
Go github.com/mattermost/mattermost/server/v8
Affected versions: 9.9.0 (fixed in 9.9.1)
Go github.com/mattermost/mattermost/server/v8
Affected versions: 0 (fixed in 8.0.0-20240604093018-5114c3b7cdb8)
Go github.com/mattermost/mattermost
Affected versions: 0 (fixed in 5.3.2-0.20240604093018-5114c3b7cdb8)

Related CVEs

Key Information

GHSA ID
GHSA-9fpw-c9x7-cv3j
Published
August 1, 2024 3:32 PM
Last Modified
July 9, 2025 4:41 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
github.com/mattermost/mattermost/server/v8
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 2, 2025 6:46 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.