CVE-2017-18910: Medium severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links.
Affected Software
3 affected components
Mattermost Mattermost Server<3.6.7
Mattermost Mattermost Server>=3.7.0<3.7.5
Mattermost Mattermost Server>=3.8.0<3.8.2
Event History
Jun 19, 2020
CVE Published
via MITRE·06:45 PM
Data Sourced
via MITRE·06:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18910?
CVE-2017-18910 is classified as a low severity vulnerability.
2
How do I fix CVE-2017-18910?
To fix CVE-2017-18910, upgrade Mattermost Server to version 3.8.2 or later, or to version 3.7.5 or later, or to version 3.6.7.
3
What type of vulnerability is CVE-2017-18910?
CVE-2017-18910 is a link spoofing vulnerability affecting email notifications.
4
Which versions of Mattermost Server are affected by CVE-2017-18910?
Mattermost Server versions prior to 3.6.7, 3.7.5, and 3.8.2 are affected by CVE-2017-18910.
5
What impact does CVE-2017-18910 have on users?
CVE-2017-18910 allows attackers to spoof links in email notifications, potentially leading to phishing attacks.