First published: Fri Jun 19 2020(Updated: )
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost | <3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-11074 has been assessed with moderate severity due to the potential for unauthorized password resets.
To fix CVE-2016-11074, update Mattermost Server to version 3.0.0 or later.
CVE-2016-11074 addresses the vulnerability that allows password-reset links to be reused.
CVE-2016-11074 affects all versions of Mattermost Server prior to 3.0.0.
CVE-2016-11074 is no longer a risk for users who have upgraded to Mattermost Server version 3.0.0 or later.