Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-18909

Опубликовано: 19 июн. 2020
Источник: debian

Описание

An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mattermost-serveritppackage

Связанные уязвимости

CVSS3: 7.5
nvd
около 6 лет назад

An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.

CVSS3: 7.5
github
больше 4 лет назад

Mattermost Server SAML implementation does not require encryption or signature verification as default