Launch Week Day 1: Announcing Security Design Review
HIGH 8.1 Go

Mattermost Server has intermittent Authorization bypass for resource-owners

GHSA-gg42-mwr6-p82c · CVE-2017-18894 · GO-2026-4297

Published · Modified

Description

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Resource-owner authorization can be intermittently bypassed, allowing account takeover.

Ready to move

Start Securing

Free, no credit card | First findings in minutes