Incorrect Implementation of Authentication Algorithm
CVE-2024-10214
Summary
Mattermost versions 9.5.x prior to 9.5.10-rc1, 9.11.x prior to 9.11.2-rc1, incorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.
- LOW
- NETWORK
- NONE
- UNCHANGED
- REQUIRED
- LOW
- LOW
- NONE
CWE-303 - Incorrect Implementation of Authentication Algorithm
The requirements for the software dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
References
Advisory Timeline
- Published