CVE-2017-1000489: High severity mautic vulnerability
Impact Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address
Patches Upgrade to 2.12.0 or later.
Workarounds None.
For more information If you have any questions or comments about this advisory: Email us at security@mautic.org
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-1000489 vulnerability?
CVE-2017-1000489 is a vulnerability in Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed that could allow a disabled user to still login using an email address.
How severe is CVE-2017-1000489?
CVE-2017-1000489 has a severity score of 8.1 (high severity).
How can I fix CVE-2017-1000489?
To fix CVE-2017-1000489, you should upgrade to Mautic version 2.12.0 or later.
Are there any workarounds for CVE-2017-1000489?
No, there are no known workarounds for CVE-2017-1000489.
Where can I find more information about CVE-2017-1000489?
You can find more information about CVE-2017-1000489 on the GitHub Security Advisory and NIST NVD websites.