SB2020061932 - Multiple vulnerabilities in Mattermost, Mattermost Server



SB2020061932 - Multiple vulnerabilities in Mattermost, Mattermost Server

Published: June 19, 2020 Updated: July 17, 2020

Security Bulletin ID SB2020061932
Severity
High
Patch available
YES
Number of vulnerabilities 8
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 13% Medium 50% Low 38%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 8 secuirty vulnerabilities.


1) Open redirect (CVE-ID: CVE-2017-18891)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.


2) Cross-site scripting (CVE-ID: CVE-2017-18893)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.


3) Incorrect permission assignment for critical resource (CVE-ID: CVE-2017-18894)

The vulnerability allows a remote authenticated user to read and manipulate data.

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.


4) Information disclosure (CVE-ID: CVE-2017-18895)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive information (user statuses) via a REST API version 4 endpoint.


5) Incorrect permission assignment for critical resource (CVE-ID: CVE-2017-18896)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint.


6) Open redirect (CVE-ID: CVE-2017-18897)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.


7) Improper Resource Shutdown or Release (CVE-ID: CVE-2017-18898)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially cause a web browser to hang.


8) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2017-18899)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.


Remediation

Install update from vendor's website.