CVE-2017-18886
published 2020-06-19CVE-2017-18886: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
PriorityP345high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.95%
57.5th percentile
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 4.1.2+incompatible | 4.1.2+incompatible |
| github.com | mattermost_mattermost-server | >= 0 < 4.1.2 | 4.1.2 |
| github.com | mattermost_mattermost-server | >= 4.2.0-rc1 < 4.2.1 | 4.2.1 |
| github.com | mattermost_mattermost-server | >= 4.2.0-rc1+incompatible < 4.2.1+incompatible | 4.2.1+incompatible |
| github.com | mattermost_mattermost-server | >= 4.3.0-rc1 < 4.3.0 | 4.3.0 |
| github.com | mattermost_mattermost-server | >= 4.3.0-rc1+incompatible < 4.3.0+incompatible | 4.3.0+incompatible |
| mattermost | mattermost_server | < 4.1.2 | 4.1.2 |
| mattermost | mattermost_server | — | — |
| mattermost | mattermost_server | >= 4.2.0 < 4.2.1 | 4.2.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost Server does not properly restrict use of slash commands in github.com/mattermost/mattermost-server
osv·2025-12-15
CVE-2017-18886 Mattermost Server does not properly restrict use of slash commands in github.com/mattermost/mattermost-server
Mattermost Server does not properly restrict use of slash commands in github.com/mattermost/mattermost-server
Mattermost Server does not properly restrict use of slash commands in github.com/mattermost/mattermost-server
OSV
Mattermost Server does not properly restrict use of slash commands
osv·2022-05-24
CVE-2017-18886 [HIGH] Mattermost Server does not properly restrict use of slash commands
Mattermost Server does not properly restrict use of slash commands
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
GHSA
Mattermost Server does not properly restrict use of slash commands
ghsa·2022-05-24
CVE-2017-18886 [HIGH] CWE-732 Mattermost Server does not properly restrict use of slash commands
Mattermost Server does not properly restrict use of slash commands
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-19
Published