CVE-2017-18920: Critical severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy.
Affected Software
1 affected component
Mattermost Mattermost Server<3.6.2
Event History
Jun 19, 2020
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-18920.
2
What is the severity of the vulnerability?
The severity of the vulnerability is rated as critical with a CVSS score of 9.8.
3
What is the affected software?
The affected software is Mattermost Server before version 3.6.2.
4
What is the impact of the vulnerability?
The vulnerability allows an attacker to bypass the Same Origin Policy and potentially perform unauthorized actions.
5
How can I fix this vulnerability?
To fix this vulnerability, update your Mattermost Server to version 3.6.2 or later.