CVE-2017-18878
published 2020-06-19CVE-2017-18878: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 4.1.2-0.20171004201910-6be8113eb60c | 4.1.2-0.20171004201910-6be8113eb60c |
| github.com | mattermost_mattermost-server | >= 4.2.0-rc1 < 4.2.1-0.20171004192657-8fbbd688ea24 | 4.2.1-0.20171004192657-8fbbd688ea24 |
| github.com | mattermost_mattermost-server | >= 4.3.0-rc1 < 4.3.0 | 4.3.0 |
| github.com | mattermost_mattermost-server | >= 4.3.0-rc1+incompatible < 4.3.0+incompatible | 4.3.0+incompatible |
| mattermost | mattermost_server | < 4.1.2 | 4.1.2 |
| mattermost | mattermost_server | — | — |
| mattermost | mattermost_server | >= 4.2.0 < 4.2.1 | 4.2.1 |