CVE-2017-18905

MEDIUM

Mattermost Server <4.0.0-3.9.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://mattermost.com/security-updates/

Scores

CVSS v3 5.3
EPSS 0.0019
EPSS Percentile 41.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-613
Status published
Products (2)
mattermost/mattermost-server 0 - 3.9.2Go
mattermost/mattermost_server < 3.9.2
Published Jun 19, 2020
Tracked Since Feb 18, 2026