Mattermost Server has Insufficient Session Expiration when used as an OAuth 2.0 service provider in github.com/mattermost/mattermost-server
Mattermost Server has Insufficient Session Expiration when used as an OAuth 2.0 service provider in github.com/mattermost/mattermost-server
02 / AFFECTED SOFTWARE
Affected packages
7 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.
Mattermost Server has Insufficient Session Expiration when used as an OAuth 2.0 service provider in github.com/mattermost/mattermost-server
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.
05 / REFERENCES
Further evidence
- https://mattermost.com/security-updates/
- https://github.com/advisories/GHSA-g24c-fx4v-xg9w
- https://github.com/mattermost/mattermost/commit/15ad24d160cb4604d0605ebbfa53d11a57820706
- https://github.com/mattermost/mattermost/commit/b17fca0d5ee7557e3df1cf1d1da8bd749859e35f
- https://github.com/mattermost/mattermost/commit/fbc170733e86f09b46ba754dd03304733d2f482f
- https://mattermost.com/security-updates
- https://nvd.nist.gov/vuln/detail/CVE-2017-18905
- https://github.com/mattermost/mattermost