描述
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.
AI分析AI驱动
受影响产品
mattermostmattermost_server
mattermostmattermost_server
mattermostmattermost_server
mattermostmattermost_server
参考资料
- https://mattermost.com/security-updatesVendor Advisory