CVE-2017-18908: Critical severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-mail address.
Affected Software
2 affected components
Mattermost Mattermost Server<3.9.2
Mattermost Mattermost Server>=3.10.0<3.10.2
Event History
Jun 19, 2020
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-18908.
2
What is the severity of CVE-2017-18908?
CVE-2017-18908 has a severity rating of 9.8 (critical).
3
What is the affected software?
The affected software is Mattermost Server versions before 4.0.0, 3.10.2, and 3.9.2.
4
What is the description of CVE-2017-18908?
CVE-2017-18908 is an issue in Mattermost Server where a password-reset request is sometimes sent to an attacker-provided email address.
5
How can I fix CVE-2017-18908?
To fix CVE-2017-18908, it is recommended to update to Mattermost Server version 4.0.0 or later.