CVE-2021-37859: Reflected XSS in OAuth Flow
Published Aug 5, 2021
·Updated
Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.
Affected Software
3 affected components
Mattermost Mattermost>=5.32.0<5.34.5
Mattermost Mattermost>=5.35.0<5.35.4
Mattermost Mattermost>=5.36.0<5.36.1
Event History
Aug 5, 2021
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-37859.
2
What is the severity of CVE-2021-37859?
The severity of CVE-2021-37859 is high.
3
What is the affected software?
The affected software is Mattermost.
4
Which versions of Mattermost are affected by CVE-2021-37859?
Versions 5.32.0 to 5.34.5, 5.35.0 to 5.35.4, and 5.36.0 to 5.36.1 of Mattermost are affected by CVE-2021-37859.
5
How can I fix the CVE-2021-37859 vulnerability?
You can fix the CVE-2021-37859 vulnerability by applying the fix provided by Mattermost through their security updates.