Incorrect Default Permissions
CVE-2017-18915
Summary
An issue was discovered in Mattermost Server 3.8.x prior to 3.8.2, 3.7.x prior to 3.7.5, and versions prior to 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoint access.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-276 - Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
Advisory Timeline
- Published