CVE-2024-5270: SAML to email switch possible when email signin is disabled
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is enabled when a user requests to switch from SAML to Email. This allows the user to switch their authentication mail from SAML to email and possibly edit personal details that were otherwise non-editable and provided by the SAML provider.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.8.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.5.4 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.7.2 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.6.2 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 8.1.13
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5270?
CVE-2024-5270 is classified as a medium severity vulnerability due to improper validation in authentication methods.
How do I fix CVE-2024-5270?
To fix CVE-2024-5270, upgrade to Mattermost versions 9.5.4, 9.6.2, 9.7.2 or later.
Which Mattermost versions are affected by CVE-2024-5270?
CVE-2024-5270 affects Mattermost versions 9.5.x up to 9.5.3, 9.6.x up to 9.6.1, 9.7.x up to 9.7.1, and 8.1.x up to 8.1.12.
What vulnerability does CVE-2024-5270 exploit?
CVE-2024-5270 exploits the failure to properly check email signup configuration when users switch authentication methods.
Is user data at risk due to CVE-2024-5270?
Yes, CVE-2024-5270 could potentially expose user accounts to unauthorized access if exploited.