Privilege Escalation Vulnerability in Mattermost Server by Mattermost
CVE-2017-18885

9.8CRITICAL

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
19 June 2020

What is CVE-2017-18885?

An issue exists in Mattermost Server versions prior to 4.3.0, 4.2.1, and 4.1.2 where attackers can exploit unintended API endpoints to gain elevated privileges. This vulnerability poses a risk of unauthorized actions being performed on behalf of legitimate users, thereby compromising the integrity of user data and system security. It is crucial for users to update to the latest version to mitigate this risk.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.