PT-2020-8005 · Mattermost · Mattermost Server
Published
2020-06-19
·
Updated
2025-11-07
·
CVE-2016-11076
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Mattermost Server versions prior to 3.0.0
Description:
The issue arises because the software does not ensure that a cookie is used over SSL. This could potentially expose sensitive information.
Recommendations:
For versions prior to 3.0.0, update to version 3.0.0 or later to ensure that cookies are used over SSL. As a temporary workaround, consider configuring the server to only use SSL connections to mitigate the risk of exploitation. Restrict access to sensitive areas of the server until the update is applied.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mattermost Server