CVE-2017-18876
published 2020-06-19CVE-2017-18876: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of…
medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 4.1.2-0.20171004201910-6be8113eb60c | 4.1.2-0.20171004201910-6be8113eb60c |
| github.com | mattermost_mattermost-server | >= 4.2.0-rc1.0.20171004154238-fadd9514f6e7 < 4.2.1-0.20171004194140-6d3cb2ce07fc | 4.2.1-0.20171004194140-6d3cb2ce07fc |
| github.com | mattermost_mattermost-server | >= 4.3.0-rc1 < 4.3.0 | 4.3.0 |
| github.com | mattermost_mattermost-server | >= 4.3.0-rc1+incompatible < 4.3.0+incompatible | 4.3.0+incompatible |
| mattermost | mattermost_server | < 4.1.2 | 4.1.2 |
| mattermost | mattermost_server | — | — |
| mattermost | mattermost_server | >= 4.2.0 < 4.2.1 | 4.2.1 |