First published: Fri Jun 19 2020(Updated: )
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost | <4.5.2 | |
Mattermost | >=4.6.0<4.6.2 | |
Mattermost | =4.7.0-rc1 | |
Mattermost | =4.7.0-rc2 | |
Mattermost | =4.7.0-rc3 | |
Mattermost | =4.7.0-rc4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-21264 has a medium severity rating due to the lack of enforced expiration dates on SAML responses.
To fix CVE-2018-21264, you should upgrade Mattermost Server to version 4.7.0 or later.
CVE-2018-21264 affects Mattermost Server versions up to 4.5.2, as well as versions 4.6.0 and 4.6.1.
CVE-2018-21264 is a security vulnerability related to SAML authentication protocols.
Yes, there is a patch available in the newer versions of Mattermost Server, starting from version 4.7.0.