Mattermost fails to check if an admin user account active...
Moderate severity
Unreviewed
Published
Jun 16, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Jun 16, 2023
Published to the GitHub Advisory Database
Jun 16, 2023
Last updated
Apr 4, 2024
Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.
References