PT-2022-15258 · Mattermost · Mattermost+1

Published

2022-01-13

·

Updated

2022-02-02

·

CVE-2022-22122

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Mattermost Focalboard versions prior to v0.7.5 Mattermost Focalboard versions prior to v0.8.4 Mattermost Focalboard versions prior to v0.9.5 Mattermost Focalboard versions prior to v0.10.1 Mattermost Focalboard versions prior to v0.11.0-rc1 Mattermost versions prior to v5.37.6 Mattermost versions prior to v5.39.3 Mattermost versions prior to v6.0.4 Mattermost versions prior to v6.1.1 Mattermost versions prior to v6.2.0
Description The issue is related to Insufficient Session Expiration. When a user logs out, their session is not properly invalidated. Additionally, user sessions are stored in the browser's local storage, which does not have an expiration time by default. This allows an attacker to steal and reuse cookies using techniques like XSS attacks, potentially taking over a victim's account.
Recommendations For Mattermost Focalboard versions prior to v0.7.5, update to version v0.7.5 or later. For Mattermost Focalboard versions prior to v0.8.4, update to version v0.8.4 or later. For Mattermost Focalboard versions prior to v0.9.5, update to version v0.9.5 or later. For Mattermost Focalboard versions prior to v0.10.1, update to version v0.10.1 or later. For Mattermost Focalboard versions prior to v0.11.0-rc1, update to version v0.11.0-rc1 or later. For Mattermost versions prior to v5.37.6, update to version v5.37.6 or later. For Mattermost versions prior to v5.39.3, update to version v5.39.3 or later. For Mattermost versions prior to v6.0.4, update to version v6.0.4 or later. For Mattermost versions prior to v6.1.1, update to version v6.1.1 or later. For Mattermost versions prior to v6.2.0, update to version v6.2.0 or later.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-22122

Affected Products

Mattermost
Mattermost Focalboard