Description
Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the malicious server and forcing a modal popup that cannot be closed.
Problem types
CWE-754: Improper Check for Unusual or Exceptional Conditions
Product status
Any version
5.13.1.0
Credits
Doyensec
References
mattermost.com/security-updates