CVE-2017-18912: Path Traversal
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file.
Affected Software
3 affected components
Mattermost Mattermost Server<3.6.7
Mattermost Mattermost Server>=3.7.0<3.7.5
Mattermost Mattermost Server>=3.8.0<3.8.2
Event History
Jun 19, 2020
CVE Published
via MITRE·06:45 PM
Data Sourced
via MITRE·06:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18912?
CVE-2017-18912 has been classified as a medium severity vulnerability due to its potential to expose sensitive log information.
2
How do I fix CVE-2017-18912?
To fix CVE-2017-18912, upgrade Mattermost Server to version 3.8.2 or later, or to version 3.7.5 or later.
3
What impact does CVE-2017-18912 have on users?
CVE-2017-18912 allows attackers to manipulate log file paths, which can lead to unauthorized access to sensitive information.
4
Which versions of Mattermost Server are affected by CVE-2017-18912?
CVE-2017-18912 affects Mattermost Server versions prior to 3.8.2, 3.7.5, and 3.6.7.
5
Is there any workaround available for CVE-2017-18912?
There are no specific workarounds for CVE-2017-18912; the recommended action is to upgrade to a secure version.