PT-2020-8465 · Mattermost · Mattermost Server
Published
2020-06-19
·
Updated
2020-06-25
·
CVE-2017-18919
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Mattermost Server versions prior to 3.7.0
Mattermost Server version 3.6.3 and earlier
Description:
An issue was discovered that allows attackers to use the API for unauthenticated team creation.
Recommendations:
For Mattermost Server versions prior to 3.7.0, update to version 3.7.0 or later.
For Mattermost Server version 3.6.3 and earlier, update to version 3.6.3 or later, or consider updating to version 3.7.0 or later for the latest security fixes.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost Server