CVE-2017-18905

MEDIUM5.3EPSS 0.19%

Mattermost Server has Insufficient Session Expiration when used as an OAuth 2.0 service provider

Published: 5/24/2022Modified: 2/3/2026
Also known as:GHSA-g24c-fx4v-xg9wGO-2026-4306

Description

An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

References (7)