GHSA-6x98-fx9j-7c78
Dashboard / Vulnerabilities / GHSA-6x98-fx9j-7c78
Summary: Disabled users able to log in with third party SSO plugin
Details: ### Impact Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address ### Patches Upgrade to 2.12.0 or later. ### Workarounds None. ### For more information If you have any questions or comments about this advisory: * Email us at [[email protected]](mailto:[email protected])
References: https://github.com/mautic/mautic/security/advisories/GHSA-6x98-fx9j-7c78, https://nvd.nist.gov/vuln/detail/CVE-2017-1000489, https://github.com/mautic/mautic/commit/fd933cbef795b04cabdc50527cb18e037488fef9, https://github.com/mautic/mautic/releases/tag/2.12.0
Affected packages
Package
Name: mautic/core
Purl: pkg:composer/mautic/core
Affected ranges
Type: ECOSYSTEM
Events:
