OAuth App Reconfiguration Vulnerability in Mattermost Server

OAuth App Reconfiguration Vulnerability in Mattermost Server

CVE-2017-18872 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.

Learn more about our Cis Benchmark Audit For Server Software.