CVE-2018-21264: Input Validation
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response.
Affected Software
6 affected components
Mattermost Mattermost Server<4.5.2
Mattermost Mattermost Server>=4.6.0<4.6.2
Mattermost Mattermost Server=4.7.0-rc1
Mattermost Mattermost Server=4.7.0-rc2
Mattermost Mattermost Server=4.7.0-rc3
Mattermost Mattermost Server=4.7.0-rc4
Event History
Jun 19, 2020
CVE Published
via MITRE·05:44 PM
Data Sourced
via MITRE·05:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-21264?
CVE-2018-21264 has a medium severity rating due to the lack of enforced expiration dates on SAML responses.
2
How do I fix CVE-2018-21264?
To fix CVE-2018-21264, you should upgrade Mattermost Server to version 4.7.0 or later.
3
Which versions of Mattermost Server are affected by CVE-2018-21264?
CVE-2018-21264 affects Mattermost Server versions up to 4.5.2, as well as versions 4.6.0 and 4.6.1.
4
What type of vulnerability is CVE-2018-21264?
CVE-2018-21264 is a security vulnerability related to SAML authentication protocols.
5
Is there a patch for CVE-2018-21264?
Yes, there is a patch available in the newer versions of Mattermost Server, starting from version 4.7.0.