PT-2020-8894 · Mattermost · Mattermost Server

Published

2020-06-19

·

Updated

2020-06-26

·

CVE-2018-21251

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mattermost Server versions prior to 5.2 Mattermost Server version 5.1.1 and earlier
Description An issue allows authorization to be bypassed if the channel name in the parameters and the body are not the same.
Recommendations For Mattermost Server versions prior to 5.2, update to version 5.2 or later to resolve the issue. For Mattermost Server version 5.1.1 and earlier, update to version 5.1.1 or later to resolve the issue. As a temporary workaround, consider validating that the channel name in the parameters matches the channel name in the body to prevent authorization bypass.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-21251

Affected Products

Mattermost Server