CVE-2018-21263: High severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response.
Affected Software
6 affected components
Mattermost Mattermost Server<4.5.2
Mattermost Mattermost Server>=4.6.0<4.6.2
Mattermost Mattermost Server=4.7.0-rc1
Mattermost Mattermost Server=4.7.0-rc2
Mattermost Mattermost Server=4.7.0-rc3
Mattermost Mattermost Server=4.7.0-rc4
Event History
Jun 19, 2020
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-21263?
CVE-2018-21263 has a medium severity rating due to the potential for unauthorized account access.
2
How do I fix CVE-2018-21263?
To fix CVE-2018-21263, upgrade Mattermost Server to version 4.7.0 or later.
3
Which versions of Mattermost Server are affected by CVE-2018-21263?
CVE-2018-21263 affects Mattermost Server versions prior to 4.7.0 and versions 4.6.2 and 4.5.2.
4
Can attackers exploit CVE-2018-21263 without user interaction?
Yes, attackers can exploit CVE-2018-21263 using a crafted SAML response, which requires no user interaction.
5
What type of attack does CVE-2018-21263 facilitate?
CVE-2018-21263 facilitates an authentication bypass attack, allowing an attacker to authenticate as another user.