CVE-2024-10214: Incorrect Session Creation with Desktop SSO
Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.
Other sources
Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 incorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.
— GitHub
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10214?
CVE-2024-10214 is considered a medium severity vulnerability due to the incorrect session handling.
How do I fix CVE-2024-10214?
To fix CVE-2024-10214, upgrade Mattermost to a version later than 9.11.1 or 9.5.9.
What versions of Mattermost are affected by CVE-2024-10214?
Mattermost versions 9.11.X up to and including 9.11.1 and 9.5.x up to and including 9.5.9 are affected by CVE-2024-10214.
What impact does CVE-2024-10214 have on Mattermost users?
CVE-2024-10214 can lead to issues with session management, potentially causing security risks and user confusion.
Is CVE-2024-10214 related to single sign-on functionality?
Yes, CVE-2024-10214 specifically involves incorrect session issuance when using desktop single sign-on (SSO) with Mattermost.