Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.7.0, <= 10.7.0
- >= 10.6.0, <= 10.6.2
- >= 10.5.0, <= 10.5.3
- >= 9.11.0, <= 9.11.12
A vulnerability exists in Mattermost versions 10.7.x through 10.7.0, 10.6.x through 10.6.2, 10.5.x through 10.5.3, and 9.11.x through 9.11.12. These versions fail to properly clear Google OAuth credentials when user accounts are converted to bot accounts. This oversight allows attackers to gain unauthorized access to bot accounts through the Google OAuth signup process.
Exploitation of this vulnerability could lead to unauthorized access to bot accounts.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.