Description
Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions
Problem types
CWE-918: Server-Side Request Forgery (SSRF)
Product status
10.10.0
10.5.9
10.5.0
Credits
Juho Forsén
References
mattermost.com/security-updates