Improper Server Redirection in Mattermost Desktop App
CVE-2020-14454

6.1MEDIUM

Key Information:

Vendor
Mattermost
Vendor
CVE Published:
19 June 2020

Summary

A security flaw was identified in the Mattermost Desktop App prior to version 4.4.0, where attackers can exploit improper handling of server redirection. This vulnerability allows malicious actors to open untrusted web pages through the desktop application, potentially compromising user security and privacy. Users are advised to update to the latest version to mitigate risks associated with this issue.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.