CVE-2024-2450
8.8
HIGH
CVSS 3.1
EPSS 0.20%
Description
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email to SAML authentication, allowing an authenticated attacker to take over other user accounts via a crafted switch request under specific conditions.
How to fix CVE-2024-2450
To remediate CVE-2024-2450, upgrade the affected package to a fixed version below.
- Bitnami/mattermost—upgrade to 8.1.10 or later
Is CVE-2024-2450 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 8.1.0, < 8.1.10, >= 9.2.0, < 9.2.6, >= 9.3.0, < 9.3.2, >= 9.4.0, < 9.4.3 | >= 9.5.0, <= 9.5.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |