CVE-2024-11599

Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registration.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

01 Oct 2025, 18:25

Type Values Removed Values Added
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Summary
  • (es) Las versiones de Mattermost 10.0.x &lt;= 10.0.1, 10.1.x &lt;= 10.1.1, 9.11.x &lt;= 9.11.3, 9.5.x &lt;= 9.5.11 no logran validar correctamente las direcciones de correo electrónico, lo que permite que un usuario no autenticado eluda las restricciones de dominio de correo electrónico mediante una entrada cuidadosamente manipulada en el registro de correo electrónico.
First Time Mattermost
Mattermost mattermost Server

28 Nov 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-28 10:15

Updated : 2025-10-01 18:25


NVD link : CVE-2024-11599

Mitre link : CVE-2024-11599

CVE.ORG link : CVE-2024-11599


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions