CVE-2017-18885Improper Privilege Management in Mattermost Mattermost-server

Severity
9.8CRITICALNVD
EPSS
0.4%
top 38.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 19
Latest updateDec 15

Description

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDmattermost/mattermost_server4.2.04.2.1+2
Gogithub.com/mattermost_mattermost-server4.2.0-rc1+incompatible4.2.1+incompatible+5

🔴Vulnerability Details

4
OSV
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials in github.com/mattermost/mattermost-server2025-12-15
GHSA
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials2022-05-24
OSV
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials2022-05-24
CVEList
CVE-2017-18885: An issue was discovered in Mattermost Server before 42020-06-19
CVE-2017-18885 — Improper Privilege Management | cvebase