MEDIUM
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2
Published Jun 19, 2020
4.3
MEDIUMCVSS 3.1
EPSS 0.78%
Description
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
Affected products
No data.
OR
- < 4.1.2
- ≥ 4.2.0 · < 4.2.1
- 4.3.0
- 4.3.0
- 4.3.0
- 4.3.0
No data.
No Red Hat product state for this CVE.
github.com/mattermost/mattermost-server
Go
Introduced 4.3.0-rc1+incompatible Fixed 4.3.0+incompatible
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/mattermost/mattermost-server | 4.3.0-rc1+incompatible | 4.3.0+incompatible |
Remediation
No remediation recorded yet.
References (6)
- https://github.com/advisories/GHSA-h564-6gc2-fcc6 Advisory
- https://github.com/mattermost/mattermost/commit/6be8113eb60cf5ddd2dc1c3f4db05cae0c183086
- https://github.com/mattermost/mattermost/commit/8fbbd688ea2466dd0d70e9c07e9703d78f8a19a5
- https://github.com/mattermost/mattermost/commit/affd35071ea155069979fd359726296de8aa6aaf
- https://mattermost.com/security-updates x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-18878
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 19, 2020
Updated Aug 5, 2024
Reserved Jun 19, 2020
Link CVE-2017-18878
CISA Vulnrichment
GHSA-H564-6GC2-FCC6 Updated n/a