First published: Fri Dec 17 2021(Updated: )
Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | <=6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37862 is a vulnerability that affects Mattermost 6.0 and earlier versions.
CVE-2021-37862 has a severity rating of medium.
CVE-2021-37862 allows attackers to trick users into signing up using attacker-controlled email addresses during registration via a crafted invitation token.
Yes, Mattermost has released security updates to address CVE-2021-37862.
You can find more information about CVE-2021-37862 in the following links: [HackerOne](https://hackerone.com/reports/1357013) and [Mattermost Security Updates](https://mattermost.com/security-updates/).