CVE-2017-18911: Critical severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.
Affected Software
3 affected components
Mattermost Mattermost Server<3.6.7
Mattermost Mattermost Server>=3.7.0<3.7.5
Mattermost Mattermost Server>=3.8.0<3.8.2
Event History
Jun 19, 2020
CVE Published
via MITRE·06:45 PM
Data Sourced
via MITRE·06:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18911?
CVE-2017-18911 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-18911?
To fix CVE-2017-18911, upgrade Mattermost Server to version 3.8.2 or later, or to version 3.7.5 or later, or to version 3.6.7.
3
What impact does CVE-2017-18911 have on Mattermost Server?
CVE-2017-18911 allows for the potential bypass of X.509 certificate validation for TLS-based email servers, which can lead to security risks.
4
Which versions of Mattermost Server are affected by CVE-2017-18911?
CVE-2017-18911 affects Mattermost Server versions prior to 3.6.7, 3.7.5, and 3.8.2.
5
Is there a workaround for CVE-2017-18911?
There is no documented workaround for CVE-2017-18911; the best action is to update to a secure version.