Security Advisory
CVE-2017-18920
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy.