Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs.
The product does not properly verify that the source of data or communication is valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mattermost_server | Mattermost | 7.8.0 (including) | 7.8.7 (excluding) |
Mattermost_server | Mattermost | 7.9.0 (including) | 7.9.5 (excluding) |
Mattermost_server | Mattermost | 7.10.0 (including) | 7.10.3 (excluding) |