Mattermost Server exposes OAuth personal access tokens to attackers in github.com/mattermost/mattermost-server
Mattermost Server exposes OAuth personal access tokens to attackers in github.com/mattermost/mattermost-server
02 / AFFECTED SOFTWARE
Affected packages
14 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Mattermost Server exposes OAuth personal access tokens to attackers in github.com/mattermost/mattermost-server
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.
05 / REFERENCES