cbcvebase.
CVE-2017-18916
published 2020-06-19

CVE-2017-18916: An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission restriction.

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission restriction.

Affected

8 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 0 < 3.6.7-0.20170420152529-0968e4079e0a3.6.7-0.20170420152529-0968e4079e0a
github.commattermost_mattermost-server>= 3.7.0 < 3.7.53.7.5
github.commattermost_mattermost-server>= 3.7.0+incompatible < 3.7.5+incompatible3.7.5+incompatible
github.commattermost_mattermost-server>= 3.8.0 < 3.8.23.8.2
github.commattermost_mattermost-server>= 3.8.0+incompatible < 3.8.2+incompatible3.8.2+incompatible
mattermostmattermost_server< 3.6.73.6.7
mattermostmattermost_server>= 3.7.0 < 3.7.53.7.5
mattermostmattermost_server>= 3.8.0 < 3.8.23.8.2