CVE-2017-18902

MEDIUM

Mattermost Server <4.1.0-3.10.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://mattermost.com/security-updates/

Scores

CVSS v3 5.3
EPSS 0.0017
EPSS Percentile 38.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
mattermost/mattermost-server 0 - 3.10.3Go
mattermost/mattermost_server < 3.10.3
Published Jun 19, 2020
Tracked Since Feb 18, 2026