Mattermost Server vulnerable to CSRF if CORS is enabled
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.
02 / AFFECTED SOFTWARE
Affected packages
7 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.
Mattermost Server vulnerable to CSRF if CORS is enabled in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: .
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.
05 / REFERENCES
Further evidence
- https://mattermost.com/security-updates/
- https://github.com/advisories/GHSA-fcwg-45jh-5qhf
- https://github.com/mattermost/mattermost/commit/312269ad0bd166174f07f9df7391fce714601600
- https://github.com/mattermost/mattermost/commit/4519b03d95e8bfe1b2f74094673ae1a2f39f6b47
- https://github.com/mattermost/mattermost/commit/a18479df0940be8503c9b88993490741793eba9e
- https://mattermost.com/security-updates
- https://nvd.nist.gov/vuln/detail/CVE-2017-18903
- https://github.com/mattermost/mattermost