CVE-2017-18903: CSRF
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.
Affected Software
2 affected components
Mattermost Mattermost Server<3.9.2
Mattermost Mattermost Server>=3.10.0<3.10.2
Event History
Jun 19, 2020
CVE Published
via MITRE·06:44 PM
Data Sourced
via MITRE·06:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18903?
CVE-2017-18903 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2017-18903?
To fix CVE-2017-18903, upgrade Mattermost Server to version 4.0.0 or later.
3
What type of vulnerability is CVE-2017-18903?
CVE-2017-18903 is a Cross-Site Request Forgery (CSRF) vulnerability occurring when CORS is enabled.
4
Which versions of Mattermost Server are affected by CVE-2017-18903?
CVE-2017-18903 affects Mattermost Server versions before 4.0.0, including 3.10.2 and 3.9.2.
5
What are the risks associated with CVE-2017-18903?
The risks associated with CVE-2017-18903 include unauthorized actions being performed on behalf of authenticated users.