cbcvebase.
CVE-2018-21263
published 2020-06-19

CVE-2018-21263: An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response.

Affected

3 ranges
VendorProductVersion rangeFixed in
mattermostmattermost_server< 4.5.24.5.2
mattermostmattermost_server
mattermostmattermost_server>= 4.6.0 < 4.6.24.6.2