Improper Certificate Validation in Mattermost Server - CVE-2017-18909
Published: June 19, 2020 / Updated: August 8, 2020
Vulnerability identifier: #VU34211
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-18909
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
Affected software
Mattermost Server
How to mitigate CVE-2017-18909
Install update from vendor's website.
Mattermost Server - update to 3.9.0