In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/mattermost/mattermost/server/channels/app to version 10.5.13, 10.11.5, 10.12.2, 11.0.3 or higher.
github.com/mattermost/mattermost/server/channels/app is a private-cloud Slack alternative
Affected versions of this package are vulnerable to Incorrect Implementation of Authentication Algorithm. An attacker can gain unauthorized access to another user's account by leveraging a specially crafted email address when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint.
Note:
This is only exploitable if the ExperimentalEnableAuthenticationTransfer setting is enabled and the RequireEmailVerification setting is disabled.