Mattermost Mobile Apps
cpe:2.3:a:mattermost:mattermost_mobile:*:*:*:*:*:*:*
- <= 2.32.0
A vulnerability exists in Mattermost Mobile Apps in versions through 2.32.0, where the applications do not properly verify that Single Sign-On (SSO) redirect tokens come from a trusted server. This flaw enables a malicious Mattermost instance or an on-path attacker to intercept user session credentials by sending crafted tokens in URL responses.
Exploitation of this vulnerability allows for the theft of user session credentials, potentially leading to unauthorized access to user accounts.
Users can upgrade to Mattermost Mobile Apps version 2.32.1 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.