#VU29285 Improper Authentication in Mattermost Desktop App - CVE-2020-14456
Published: June 25, 2020
Mattermost Desktop App
Mattermost, Inc.
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the Same Origin Policy is mishandled during access-control decisions for web APIs which allows 3rd-party origins access to restricted web APIs. A remote attacker can bypass authentication process and gain unauthorized access to the application.