Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an attacker to perform a limited blind SSRF.
2023-07-17T16:15:10.330
2024-11-21T08:17:35.310
Modified
CVSSv3.1: 3.5 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_server | < 7.8.7 | Yes |
Application | mattermost | mattermost_server | < 7.10.3 | Yes |