Mattermost fails to clear Google OAuth credentials
Moderate severity
GitHub Reviewed
Published
May 30, 2025
to the GitHub Advisory Database
•
Updated May 30, 2025
Package
Affected versions
>= 10.7.0-rc1, < 10.7.1
>= 10.0.0-rc1, < 10.5.4
>= 9.0.0-rc1, < 9.11.13
< 8.0.0-20250414095146-04676582cdd2
>= 10.6.0-rc1, < 10.6.3
Patched versions
10.7.1
10.5.4
9.11.13
8.0.0-20250414095146-04676582cdd2
10.6.3
Description
Published by the National Vulnerability Database
May 30, 2025
Published to the GitHub Advisory Database
May 30, 2025
Reviewed
May 30, 2025
Last updated
May 30, 2025
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.
References