CVE-2021-37860: XSS
Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Do not disable Mattermost's default CSP in product deployments; ensure CSP is enabled to prevent injected web scripts via unsanitized clipboard contents.
Mattermost Content-Security-Policy (CSP) = Enabled (do not disable default CSP)
Event History
Frequently Asked Questions
What is the vulnerability ID for Mattermost?
The vulnerability ID for Mattermost is CVE-2021-37860.
What is the severity of CVE-2021-37860?
The severity of CVE-2021-37860 is medium.
How does CVE-2021-37860 affect Mattermost?
CVE-2021-37860 affects Mattermost version 5.38 and earlier by allowing a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.
How can I fix CVE-2021-37860 in my Mattermost deployment?
To fix CVE-2021-37860 in your Mattermost deployment, make sure to upgrade to a version newer than 5.38 that includes the necessary fixes and improvements.
Where can I find more information about CVE-2021-37860?
You can find more information about CVE-2021-37860 on the Mattermost website at https://mattermost.com/security-updates/.