cbcvebase.
CVE-2017-18905
published 2020-06-19

CVE-2017-18905: An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.

Affected

6 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 0 < 3.9.23.9.2
github.commattermost_mattermost-server>= 0 < 3.9.2+incompatible3.9.2+incompatible
github.commattermost_mattermost-server>= 3.10.0 < 3.10.23.10.2
github.commattermost_mattermost-server>= 3.10.0+incompatible < 3.10.2+incompatible3.10.2+incompatible
mattermostmattermost_server< 3.9.23.9.2
mattermostmattermost_server>= 3.10.0 < 3.10.23.10.2