Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Mattermost
Published: 2021-09-22T16:40:43
Updated: 2021-09-22T16:40:43
Reserved: 2021-08-02T00:00:00
Link: CVE-2021-37860
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-09-22T17:15:11.647
Modified: 2021-10-05T17:30:36.187
Link: CVE-2021-37860
JSON object: View
Redhat Information
No data.
CWE