Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/mattermost/mattermost-server/v6(Go) | 7.10.0 | 7.10.1 | N/A |
| github.com/mattermost/mattermost-server/v6(Go) | 7.9.0 | 7.9.4 | N/A |
| github.com/mattermost/mattermost-server/v6(Go) | 6.0.0 | 7.8.5 | N/A |
| github.com/mattermost/mattermost-server/v6(Go) | 0 | 6.0.0-20230511130429-1629a6ca7fed | N/A |
CVSS Metrics