Описание
Mattermost Server SAML implementation does not require encryption or signature verification as default
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
Пакеты
Наименование
github.com/mattermost/mattermost-server
go
Затронутые версииВерсия исправления
< 3.8.1-0.20170504181128-4f074fed0d65
3.8.1-0.20170504181128-4f074fed0d65
Связанные уязвимости
CVSS3: 7.5
nvd
больше 5 лет назад
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
CVSS3: 7.5
debian
больше 5 лет назад
An issue was discovered in Mattermost Server before 3.9.0 when SAML is ...