CVE-2024-2450

HIGH

Mattermost <8.1.10, <9.2.6, <9.3.2, <9.4.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email to SAML authentication, allowing an authenticated attacker to take over other user accounts via a crafted switch request under specific conditions.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0020
EPSS Percentile 41.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287 CWE-306
Status published
Products (2)
mattermost/mattermost_server 9.5.0
mattermost/mattermost_server 8.1.0 - 8.1.10
Published Mar 15, 2024
Tracked Since Feb 18, 2026