Lack of server certificate validation in websockets connection
CVE-2023-3615
8.1HIGH
What is CVE-2023-3615?
The Mattermost iOS app has a security flaw where it fails to adequately validate server certificates during TLS initialization. This vulnerability can be exploited by network attackers, potentially allowing them to intercept WebSockets communication between the app and server. Users are encouraged to update to the latest version to mitigate this risk.
Affected Version(s)
Mattermost iOS app iOS 0 <= 2.5.0
Mattermost iOS app iOS 2.5.1