CVE-2017-18915: Critical severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoint access.
Affected Software
3 affected components
Mattermost Mattermost Server>=3.6.0<3.6.7
Mattermost Mattermost Server>=3.7.0<3.7.5
Mattermost Mattermost Server>=3.8.0<3.8.2
Event History
Jun 19, 2020
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
Description
Frequently Asked Questions
1
What is CVE-2017-18915?
CVE-2017-18915 is a vulnerability in Mattermost Server before version 3.8.2, 3.7.5, and 3.6.7 that allows an attacker to gain API Endpoint access after a server restart.
2
How severe is CVE-2017-18915?
CVE-2017-18915 has a severity rating of 9.8 out of 10, making it a critical vulnerability.
3
What software versions are affected by CVE-2017-18915?
Mattermost Server versions 3.6.0 to 3.6.7, 3.7.0 to 3.7.5, and 3.8.0 to 3.8.2 are affected by CVE-2017-18915.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2017-18915?
CVE-2017-18915 is associated with CWE-276.
5
How can I fix CVE-2017-18915?
To fix CVE-2017-18915, it is recommended to upgrade Mattermost Server to version 3.8.2, 3.7.5, or 3.6.7.