CVE-2017-18870Incorrect Permission Assignment in Server

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 55.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 19
Latest updateDec 8

Description

An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

NVDmattermost/mattermost_server4.4.04.4.5+2

🔴Vulnerability Details

2
OSV
CVE-2017-18870 in github.com/mattermost/mattermost-server2025-12-08
CVEList
CVE-2017-18870: An issue was discovered in Mattermost Server before 42020-06-19
CVE-2017-18870 — Incorrect Permission Assignment | cvebase