Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in Mattermost's handling of redirect URIs for OAuth client registration. An unauthenticated attacker could exploit this by registering an OAuth client with a malicious callback host, potentially bypassing security controls and leading to unauthorized access or data exposure. The main concern is confirming relevance and exposure of Mattermost instances.
- Flaw allows unauthenticated callback host registration.
- Bypasses allowlist for OAuth client registration.
- Confirm relevance and exposure of Mattermost.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by registering a malicious OAuth client. This is possible because the system improperly validates redirect URIs when registering OAuth clients. An attacker could craft a redirect URI to bypass allowlists, leading to a callback to an attacker-controlled host.
- Unauthenticated remote attacker.
- Registering a malicious OAuth client.
- Redirect URI bypass allows callback.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated attacker to register an OAuth client with a malicious callback host, bypassing security controls when specific redirect URI patterns are used. This could potentially expose sensitive information or allow unauthorized actions when supported by the advisory.
- OAuth client registration.
- Crafted redirect URI bypasses allowlist.
- Unauthorized access or data exposure.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects Mattermost server instances and requires action from teams responsible for its operation and security. The immediate first step is to inventory all Mattermost deployments, assess their exposure and business criticality, and identify the accountable system owner for each instance. Remediation planning should then be prioritized based on this risk assessment.
- Identify Mattermost instances and owners.
- Verify reachability and business criticality.
- Plan remediation based on risk.