packages:
- package: github.com/mattermost/mattermost-server/v5
versions:
- fixed: 5.39.0
description: Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard
contents, which allows a user-assisted attacker to inject arbitrary web script
in product deployments that explicitly disable the default CSP.
published: 2021-09-23T23:11:06Z
last_modified: 2021-10-06T13:08:14Z
cves:
- CVE-2021-37860
ghsas:
- GHSA-hv5f-73mr-7vvj
links:
context:
- https://github.com/advisories/GHSA-hv5f-73mr-7vvj