Improper Certificate Validation in Mattermost Server - CVE-2017-18909

 

Improper Certificate Validation in Mattermost Server - CVE-2017-18909

Published: June 19, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34211
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-18909
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.


Affected software

Mattermost Server

How to mitigate CVE-2017-18909

Install update from vendor's website.

Mattermost Server - update to 3.9.0

External References

Related Security Bulletins