Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs. CreditsJuho NurminenReferenceshttps://mattermost.com/security-updates