An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-9995 | An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled. |
Github GHSA |
GHSA-g24c-fx4v-xg9w | Mattermost Server has Insufficient Session Expiration when used as an OAuth 2.0 service provider |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:37:44.319Z
Reserved: 2020-06-19T00:00:00.000Z
Link: CVE-2017-18905
No data.
Status : Modified
Published: 2020-06-19T20:15:12.087
Modified: 2024-11-21T03:21:13.643
Link: CVE-2017-18905
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA