CVE Vulnerabilities

CVE-2024-10214

Incorrect Implementation of Authentication Algorithm

Published: Oct 28, 2024 | Modified: Nov 05, 2024
CVSS 3.x
3.5
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.

Weakness

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Affected Software

Name Vendor Start Version End Version
Mattermost Mattermost 9.5.0 (including) 9.5.9 (including)
Mattermost Mattermost 9.11.0 (including) 9.11.1 (including)

References