CVE-2017-18886: High severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
Affected Software
6 affected components
Mattermost Mattermost Server<4.1.2
Mattermost Mattermost Server>=4.2.0<4.2.1
Mattermost Mattermost Server=4.3.0-rc1
Mattermost Mattermost Server=4.3.0-rc2
Mattermost Mattermost Server=4.3.0-rc3
Mattermost Mattermost Server=4.3.0-rc4
Event History
Jun 19, 2020
CVE Published
via MITRE·06:43 PM
Data Sourced
via MITRE·06:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18886?
CVE-2017-18886 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2017-18886?
To fix CVE-2017-18886, upgrade to Mattermost Server version 4.3.0 or later.
3
What impact does CVE-2017-18886 have on Mattermost Server?
CVE-2017-18886 allows unauthorized users to bypass restrictions on the use of slash commands.
4
Which versions of Mattermost are affected by CVE-2017-18886?
CVE-2017-18886 affects Mattermost Server versions before 4.3.0, 4.2.1, and 4.1.2.
5
Is there a workaround for CVE-2017-18886?
There are no known workarounds for CVE-2017-18886 other than applying the patch.