Low Entropy for Authorization Data in Mattermost Server

Low Entropy for Authorization Data in Mattermost Server

CVE-2017-18883 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.

Learn more about our Cis Benchmark Audit For Server Software.