CVE-2018-21251
19.06.2020, 17:15
An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.Enginsight
Vendor | Product | Version |
---|---|---|
mattermost | mattermost_server | 𝑥 < 5.1.1 |
mattermost | mattermost_server | 5.2.0:rc1 |
mattermost | mattermost_server | 5.2.0:rc2 |
mattermost | mattermost_server | 5.2.0:rc3 |
mattermost | mattermost_server | 5.2.0:rc4 |
mattermost | mattermost_server | 5.2.0:rc5 |
mattermost | mattermost_server | 5.2.0:rc6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration