CVE-2017-18885
published 2020-06-19CVE-2017-18885: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a…
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.18%
64.3th percentile
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 4.1.2+incompatible | 4.1.2+incompatible |
| github.com | mattermost_mattermost-server | >= 0 < 4.1.2 | 4.1.2 |
| github.com | mattermost_mattermost-server | >= 4.2.0-rc1 < 4.2.1 | 4.2.1 |
| github.com | mattermost_mattermost-server | >= 4.2.0-rc1+incompatible < 4.2.1+incompatible | 4.2.1+incompatible |
| github.com | mattermost_mattermost-server | >= 4.3.0-rc1 < 4.3.0 | 4.3.0 |
| github.com | mattermost_mattermost-server | >= 4.3.0-rc1+incompatible < 4.3.0+incompatible | 4.3.0+incompatible |
| mattermost | mattermost_server | < 4.1.2 | 4.1.2 |
| mattermost | mattermost_server | — | — |
| mattermost | mattermost_server | >= 4.2.0 < 4.2.1 | 4.2.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials in github.com/mattermost/mattermost-server
osv·2025-12-15
CVE-2017-18885 Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials in github.com/mattermost/mattermost-server
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials in github.com/mattermost/mattermost-server
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials in github.com/mattermost/mattermost-server
GHSA
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials
ghsa·2022-05-24
CVE-2017-18885 [CRITICAL] CWE-269 Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.
OSV
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials
osv·2022-05-24
CVE-2017-18885 [CRITICAL] Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-19
Published