MEDIUM4.3
GHSA-4ghx-8jw8-p76q
Mattermost Open Redirect vulnerability
Quick fix
GHSA-4ghx-8jw8-p76q — github.com/mattermost/mattermost/server/v8: upgrade to the fixed version with the command below.
go get github.com/mattermost/mattermost/server/v8@v9.1.1Details
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/mattermost/mattermost/server/v8
Introduced in:
9.1.0Fixed in: 9.1.1Fix
go get github.com/mattermost/mattermost/server/v8@v9.1.1Go/github.com/mattermost/mattermost/server/v8
Introduced in:
9.0.0Fixed in: 9.0.2Fix
go get github.com/mattermost/mattermost/server/v8@v9.0.2Go/github.com/mattermost/mattermost/server/v8
Introduced in:
0Fixed in: 8.1.4Fix
go get github.com/mattermost/mattermost/server/v8@v8.1.4Go/github.com/mattermost/mattermost-server/v6
Introduced in:
0Fixed in: 7.8.13Fix
go get github.com/mattermost/mattermost-server/v6@v7.8.13