In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/mattermost/mattermost/server/channels/app
to version 9.5.13-rc1, 9.11.5-rc1, 10.0.3-rc1, 10.1.3-rc1 or higher.
github.com/mattermost/mattermost/server/channels/app is a private-cloud Slack alternative
Affected versions of this package are vulnerable to Race Condition in CheckPasswordAndAllCriteria()
in authentication.go
, when handling concurrent login attempts. An attacker can send multiple login requests to bypass blocking functionality.