CVE-2017-18911
published 2020-06-19CVE-2017-18911: An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.
PriorityP344critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.67%
48.2th percentile
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 3.6.7-rc1 | 3.6.7-rc1 |
| github.com | mattermost_mattermost-server | >= 0 < 3.6.7-rc1+incompatible | 3.6.7-rc1+incompatible |
| github.com | mattermost_mattermost-server | >= 3.7.0 < 3.7.5 | 3.7.5 |
| github.com | mattermost_mattermost-server | >= 3.7.0+incompatible < 3.7.5+incompatible | 3.7.5+incompatible |
| github.com | mattermost_mattermost-server | >= 3.8.0 < 3.8.2 | 3.8.2 |
| github.com | mattermost_mattermost-server | >= 3.8.0+incompatible < 3.8.2+incompatible | 3.8.2+incompatible |
| mattermost | mattermost_server | < 3.6.7 | 3.6.7 |
| mattermost | mattermost_server | >= 3.7.0 < 3.7.5 | 3.7.5 |
| mattermost | mattermost_server | >= 3.8.0 < 3.8.2 | 3.8.2 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost Server has X.509 Improper Certificate Validation in github.com/mattermost/mattermost-server
osv·2026-02-17
CVE-2017-18911 Mattermost Server has X.509 Improper Certificate Validation in github.com/mattermost/mattermost-server
Mattermost Server has X.509 Improper Certificate Validation in github.com/mattermost/mattermost-server
Mattermost Server has X.509 Improper Certificate Validation in github.com/mattermost/mattermost-server
OSV
Mattermost Server has X.509 Improper Certificate Validation
osv·2022-05-24
CVE-2017-18911 [CRITICAL] Mattermost Server has X.509 Improper Certificate Validation
Mattermost Server has X.509 Improper Certificate Validation
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.
GHSA
Mattermost Server has X.509 Improper Certificate Validation
ghsa·2022-05-24
CVE-2017-18911 [CRITICAL] CWE-295 Mattermost Server has X.509 Improper Certificate Validation
Mattermost Server has X.509 Improper Certificate Validation
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-19
Published