PT-2020-8005 · Mattermost · Mattermost Server

Published

2020-06-19

·

Updated

2025-11-07

·

CVE-2016-11076

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mattermost Server versions prior to 3.0.0
Description: The issue arises because the software does not ensure that a cookie is used over SSL. This could potentially expose sensitive information.
Recommendations: For versions prior to 3.0.0, update to version 3.0.0 or later to ensure that cookies are used over SSL. As a temporary workaround, consider configuring the server to only use SSL connections to mitigate the risk of exploitation. Restrict access to sensitive areas of the server until the update is applied.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-11076
GHSA-379P-37XC-Q963
GO-2025-4054
OPENSUSE-SU-2025:15710-1

Affected Products

Mattermost Server