Improper Check for Unusual or Exceptional Conditions Affecting github.com/mattermost/mattermost/server/public/model package, versions >=9.5.0 <9.5.8 >=9.8.0 <9.8.3 >=9.9.0 <9.9.2 >=9.10.0 <9.10.1
Threat Intelligence
EPSS
0.05% (19th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMMATTERMOSTMATTERMOSTSERVERPUBLICMODEL-7791186
- published 22 Aug 2024
- disclosed 22 Aug 2024
- credit DoyenSec
Introduced: 22 Aug 2024
CVE-2024-42411 Open this link in a new tabHow to fix?
Upgrade github.com/mattermost/mattermost/server/public/model
to version 9.5.8, 9.8.3, 9.9.2, 9.10.1 or higher.
Overview
Affected versions of this package are vulnerable to Improper Check for Unusual or Exceptional Conditions through the POST /api/v4/users
endpoint. An attacker can trick the system administrator into believing a user account is older than it actually is by manipulating the creation date.