CVE-2017-18918: Medium severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate at an arbitrary pathname.
Affected Software
2 affected components
Mattermost Mattermost Server>=3.6.0<3.6.5
Mattermost Mattermost Server>=3.7.0<3.7.3
Event History
Jun 19, 2020
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in Mattermost Server?
The vulnerability ID for this issue in Mattermost Server is CVE-2017-18918.
2
What is the severity of CVE-2017-18918?
The severity of CVE-2017-18918 is medium with a severity value of 4.9.
3
How does the vulnerability in Mattermost Server affect the software?
The vulnerability in Mattermost Server allows a System Administrator to place a SAML certificate at an arbitrary pathname.
4
Which versions of Mattermost Server are affected by this vulnerability?
The versions of Mattermost Server affected by this vulnerability are between 3.6.0 and 3.6.5, as well as between 3.7.0 and 3.7.3.
5
How can I fix the vulnerability in Mattermost Server?
To fix the vulnerability in Mattermost Server, update to version 3.6.5 or 3.7.3.