Session Fixation Affecting github.com/mattermost/mattermost/server/channels/app package, versions <10.5.0


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMMATTERMOSTMATTERMOSTSERVERCHANNELSAPP-8745210
  • published24 Feb 2025
  • disclosed24 Feb 2025
  • crediteAhmed

Introduced: 24 Feb 2025

NewCVE-2025-1412  (opens in a new tab)
CWE-384  (opens in a new tab)

How to fix?

Upgrade github.com/mattermost/mattermost/server/channels/app to version 10.5.0 or higher.

Overview

github.com/mattermost/mattermost/server/channels/app is a private-cloud Slack alternative

Affected versions of this package are vulnerable to Session Fixation due to improper session invalidation when converting a user to a bot. When a user with an active session is converted into a bot, their existing session remains valid instead of being revoked.

CVSS Scores

version 4.0
version 3.1