Skip to main content

Incorrect Implementation of Authentication Algorithm

CVE-2024-10214

Severity Low
Score 3.5/10

Summary

Mattermost versions 9.5.x prior to 9.5.10-rc1, 9.11.x prior to 9.11.2-rc1, incorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • REQUIRED
  • LOW
  • LOW
  • NONE

CWE-303 - Incorrect Implementation of Authentication Algorithm

The requirements for the software dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Advisory Timeline

  • Published