First published: Tue Oct 29 2024(Updated: )
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/mattermost/mattermost/server/v8 | <8.0.0-20240926115259-20ed58906adc | 8.0.0-20240926115259-20ed58906adc |
Mattermost Mattermost Server | >=9.5.0<=9.5.9 | |
Mattermost Mattermost Server | >=9.10.0<=9.10.2 | |
Mattermost Mattermost Server | >=9.11.0<=9.11.1 |
Update Mattermost to versions 10.0.0, 9.10.3, 9.11.2, 9.5.10 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.