Cookie Handling Vulnerability in Mattermost Server by Mattermost
CVE-2016-11076

5.3MEDIUM

Key Information:

Vendor
Mattermost
Vendor
CVE Published:
19 June 2020

Summary

A vulnerability was identified in Mattermost Server versions prior to 3.0.0, which fails to enforce the usage of cookies over SSL. This oversight can expose sensitive information during transmission, making it susceptible to interception by malicious actors. Implementing secure cookie handling practices is essential for maintaining the integrity and confidentiality of user data.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.