An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate at an arbitrary pathname.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mattermost_server | Mattermost | 3.6.0 (including) | 3.6.5 (excluding) |
Mattermost_server | Mattermost | 3.7.0 (including) | 3.7.3 (excluding) |