CVE-2017-18872

MEDIUM

Mattermost Server <4.4.3,4.3.3 - Auth Bypass

Title source: llm
STIX 2.1

Description

An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://mattermost.com/security-updates/

Scores

CVSS v3 4.3
EPSS 0.0015
EPSS Percentile 35.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-732
Status published
Products (2)
mattermost/mattermost-server 0 - 4.3.3Go
mattermost/mattermost_server < 4.3.3
Published Jun 19, 2020
Tracked Since Feb 18, 2026