CVE-2017-18916

EPSS 0.19%

Mattermost Server has Improper Authorization for Integration Requests

Published: 5/24/2022Modified: 2/22/2026

Description

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission restriction.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

References (7)