ZeroHour

CVE-2017-18883

CVSS 3.1
9.1 critical
EPSS
1%p64
Published
()
Modified
Description

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.

Vendors
mattermost
Products
mattermost server
Weakness
CWE-331
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.