PT-2020-14014 · Mattermost · Mattermost Desktop App

Published

2020-06-19

·

Updated

2020-06-25

·

CVE-2020-14454

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost Desktop App versions prior to 4.4.0
Description An issue was discovered where server redirection is mishandled, allowing attackers to open web pages in the desktop application.
Recommendations For versions prior to 4.4.0, update to version 4.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially malicious web pages until the update is applied.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14454

Affected Products

Mattermost Desktop App