CVE-2017-18916

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission restriction.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
VendorProductVersion
mattermostmattermost_server
𝑥
< 3.6.7
mattermostmattermost_server
3.7.0 ≤
𝑥
< 3.7.5
mattermostmattermost_server
3.8.0 ≤
𝑥
< 3.8.2
𝑥
= Vulnerable software versions