CVE-2024-11599: Domain Restriction Bypass on Registration
Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registration.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11599?
CVE-2024-11599 is rated as a critical vulnerability due to its potential to allow unauthorized email registrations.
How do I fix CVE-2024-11599?
To fix CVE-2024-11599, update Mattermost to the latest patched version that addresses this email validation issue.
Which Mattermost versions are affected by CVE-2024-11599?
CVE-2024-11599 affects Mattermost versions 10.0.x up to 10.0.1, 10.1.x up to 10.1.1, 9.11.x up to 9.11.3, and 9.5.x up to 9.5.11.
Can CVE-2024-11599 be exploited without authentication?
Yes, CVE-2024-11599 can be exploited by unauthenticated users, allowing them to bypass email domain restrictions.
What type of attack does CVE-2024-11599 enable?
CVE-2024-11599 enables attackers to exploit the vulnerability to manipulate email registrations and potentially create accounts with unauthorized email addresses.