9.1

CVE-2017-18883

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.

Data is provided by the National Vulnerability Database (NVD)
MattermostMattermost Server Version < 4.1.2
MattermostMattermost Server Version >= 4.2.0 < 4.2.1
MattermostMattermost Server Version4.3.0 Updaterc1
MattermostMattermost Server Version4.3.0 Updaterc2
MattermostMattermost Server Version4.3.0 Updaterc3
MattermostMattermost Server Version4.3.0 Updaterc4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.31% 0.514
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
CWE-331 Insufficient Entropy

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.