Mattermost Server SAML implementation does not require encryption or signature verification as default
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
02 / AFFECTED SOFTWARE
Affected packages
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
Mattermost Server SAML implementation does not require encryption or signature verification as default in github.com/mattermost/mattermost-server. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.8.1-0.20170504181128-4f074fed0d65.
05 / REFERENCES
Further evidence
- https://mattermost.com/security-updates/
- https://github.com/mattermost/mattermost
- https://github.com/mattermost/mattermost/commit/4f074fed0d653a28779ac586e418341232d43e95
- https://mattermost.com/security-updates
- https://nvd.nist.gov/vuln/detail/CVE-2017-18909
- https://github.com/advisories/GHSA-r6j5-fqx9-7qv9