Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.
Solution:
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
Link | Tags |
---|---|
https://mattermost.com/security-updates | vendor advisory |