[uchat.uberinternals.com] Mattermost doesn't check Origin in Websockets, which leads to the Critical Inforamation Leakage.
Critical
U
Uber
Submitted None
Team Summary
Official summary from Uber
Thanks for the report and participation in our program, @kxyry!
Actions:
Reported by
kxyry
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$2000.00
Submitted
Weakness
Cross-Site Request Forgery (CSRF)