CVE-2017-18906
published 2020-06-19CVE-2017-18906: An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody else's…
PriorityP342high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.79%
52.5th percentile
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody else's account.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 3.9.2-0.20170714134023-b17fca0d5ee7 | 3.9.2-0.20170714134023-b17fca0d5ee7 |
| github.com | mattermost_mattermost-server | >= 3.10.0 < 3.10.2 | 3.10.2 |
| github.com | mattermost_mattermost-server | >= 3.10.0+incompatible < 3.10.2+incompatible | 3.10.2+incompatible |
| mattermost | mattermost_server | < 3.9.2 | 3.9.2 |
| mattermost | mattermost_server | >= 3.10.0 < 3.10.2 | 3.10.2 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used in github.com/mattermost/mattermost-server
osv·2026-02-17
CVE-2017-18906 Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used in github.com/mattermost/mattermost-server
Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used in github.com/mattermost/mattermost-server
Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server before v3.9.2-0.20170714134023-b17fca0d5ee7.
GHSA
Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used
ghsa·2022-05-24
CVE-2017-18906 [HIGH] CWE-613 Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used
Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody else's account.
OSV
Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used
osv·2022-05-24
CVE-2017-18906 [HIGH] Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used
Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody else's account.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-19
Published