Home
MEDIUM: 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:NDefault status
unaffected
Any version
affected
2.33.0
unaffected
Description
Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via crafted token-in-URL responses
Problem types
CWE-352: Cross-Site Request Forgery (CSRF)
Product status
Any version
2.33.0
Credits
Doyensec
References
mattermost.com/security-updates