An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
mitre·CWE-295·Published 2020-06-19
Mattermost Server does not check if cookies are used over SSL in github.com/mattermost/mattermost-server