Related Vulnerabilities: CVE-2021-37860  

Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.

Severity Low

Remote Yes

Type Cross-site scripting

Description

Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.

AVG-2416 mattermost 5.38.2-1 5.39.0-1 Low Fixed

https://mattermost.com/security-updates/