CVE-2017-18906: High severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody else's account.
Affected Software
2 affected components
Mattermost Mattermost Server<3.9.2
Mattermost Mattermost Server>=3.10.0<3.10.2
Event History
Jun 19, 2020
CVE Published
via MITRE·07:18 PM
Data Sourced
via MITRE·07:18 PM
Description
Frequently Asked Questions
1
What is CVE-2017-18906?
CVE-2017-18906 is a vulnerability in Mattermost Server versions before 4.0.0, 3.10.2, and 3.9.2 that affects Single Sign-On OAuth2.
2
How severe is CVE-2017-18906?
CVE-2017-18906 has a severity rating of 8.1, which is considered high.
3
How does CVE-2017-18906 affect Mattermost Server?
CVE-2017-18906 allows an attacker to claim somebody else's account when Single Sign-On OAuth2 is used.
4
Which versions of Mattermost Server are affected by CVE-2017-18906?
Mattermost Server versions before 4.0.0, 3.10.2, and 3.9.2 are affected by CVE-2017-18906.
5
How can I fix CVE-2017-18906?
To fix CVE-2017-18906, it is recommended to update Mattermost Server to version 4.0.0 or later.