Cookie Handling Vulnerability in Mattermost Server by Mattermost
CVE-2016-11076
5.3MEDIUM
Summary
A vulnerability was identified in Mattermost Server versions prior to 3.0.0, which fails to enforce the usage of cookies over SSL. This oversight can expose sensitive information during transmission, making it susceptible to interception by malicious actors. Implementing secure cookie handling practices is essential for maintaining the integrity and confidentiality of user data.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved