Total vulnerabilities in the database
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.
Software | From | Fixed in |
---|---|---|
mattermost / mattermost_server | 5.9.0-rc2 | 5.9.0-rc2.x |
mattermost / mattermost_server | 5.9.0-rc3 | 5.9.0-rc3.x |
mattermost / mattermost_server | 5.9.0-rc4 | 5.9.0-rc4.x |
mattermost / mattermost_server | 5.9.0-rc1 | 5.9.0-rc1.x |
mattermost / mattermost_server | 5.8.0 | 5.8.1 |
mattermost / mattermost_server | 5.7.0 | 5.7.3 |
mattermost / mattermost_server | - | 4.10.8 |