CVE-2017-18890: Input Validation
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker to create a button that, when pressed by a user, launches an API request.
Affected Software
6 affected components
Mattermost Mattermost Server<4.1.2
Mattermost Mattermost Server>=4.2.0<4.2.1
Mattermost Mattermost Server=4.3.0-rc1
Mattermost Mattermost Server=4.3.0-rc2
Mattermost Mattermost Server=4.3.0-rc3
Mattermost Mattermost Server=4.3.0-rc4
Event History
Jun 19, 2020
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18890?
CVE-2017-18890 is classified as a high severity vulnerability due to its potential for unauthorized API requests.
2
How do I fix CVE-2017-18890?
To fix CVE-2017-18890, upgrade Mattermost Server to version 4.3.0 or later.
3
Who is affected by CVE-2017-18890?
CVE-2017-18890 affects Mattermost Server versions before 4.3.0, 4.2.1, and 4.1.2.
4
What type of attack does CVE-2017-18890 enable?
CVE-2017-18890 enables attackers to create buttons that can trigger API requests when activated by users.
5
Is there a specific release where CVE-2017-18890 was fixed?
Yes, CVE-2017-18890 was fixed in the release of Mattermost Server 4.3.0.