SB2020061932 - Multiple vulnerabilities in Mattermost, Mattermost Server
Published: June 19, 2020 Updated: July 17, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 secuirty vulnerabilities.
1) Open redirect (CVE-ID: CVE-2017-18891)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
2) Cross-site scripting (CVE-ID: CVE-2017-18893)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.
3) Incorrect permission assignment for critical resource (CVE-ID: CVE-2017-18894)
The vulnerability allows a remote authenticated user to read and manipulate data.
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.
4) Information disclosure (CVE-ID: CVE-2017-18895)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive information (user statuses) via a REST API version 4 endpoint.
5) Incorrect permission assignment for critical resource (CVE-ID: CVE-2017-18896)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint.
6) Open redirect (CVE-ID: CVE-2017-18897)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.
7) Improper Resource Shutdown or Release (CVE-ID: CVE-2017-18898)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially cause a web browser to hang.
8) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2017-18899)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.
Remediation
Install update from vendor's website.