PT-2020-8465 · Mattermost · Mattermost Server

Published

2020-06-19

·

Updated

2020-06-25

·

CVE-2017-18919

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mattermost Server versions prior to 3.7.0 Mattermost Server version 3.6.3 and earlier
Description: An issue was discovered that allows attackers to use the API for unauthenticated team creation.
Recommendations: For Mattermost Server versions prior to 3.7.0, update to version 3.7.0 or later. For Mattermost Server version 3.6.3 and earlier, update to version 3.6.3 or later, or consider updating to version 3.7.0 or later for the latest security fixes.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18919

Affected Products

Mattermost Server