GHSA-hgrp-fgm8-56g8
Dashboard / Vulnerabilities / GHSA-hgrp-fgm8-56g8
GHSA-hgrp-fgm8-56g8
Summary: Mattermost Server's OAuth 2.0 service is vulnerable to attack through Missing Authorization
Details: An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-18872, https://github.com/mattermost/mattermost/commit/8f6bb1570dd234c63de5241eff9fbb268aad358c, https://github.com/mattermost/mattermost, https://mattermost.com/security-updates, http://github.com/mattermost/mattermost/commit/753386c2b2b06233d8bd977e3db29a4fe18098cb
Affected packages
Package
Name: github.com/mattermost/mattermost-server
Purl: pkg:golang/github.com/mattermost/mattermost-server
Affected ranges
Type: SEMVER
Events:
