An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.
{
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "4.4.0"
}
]
}