PT-2020-8461 · Mattermost · Mattermost Server

Published

2020-06-19

·

Updated

2026-03-03

·

CVE-2017-18915

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Mattermost Server versions prior to 3.8.2 Mattermost Server versions prior to 3.7.5 Mattermost Server versions prior to 3.6.7
Description: An issue was discovered in Mattermost Server. After a restart of a server, an attacker might suddenly gain API Endpoint access.
Recommendations: For versions prior to 3.8.2, update to version 3.8.2 or later. For versions prior to 3.7.5, update to version 3.7.5 or later. For versions prior to 3.6.7, update to version 3.6.7 or later.

Fix

RCE

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2017-18915
GHSA-HXXJ-8PHW-74VW
GO-2026-4462
SUSE-SU-2026:0757-1

Affected Products

Mattermost Server