LiveActive security incident?Get immediate response
CVE Record

CVE-2018-21265: An issue was discovered in Mattermost Desktop App before 4.0.0.

An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

Mattermost Desktop App versions before 4.0.0 mishandled browser permission requests for capabilities such as camera, microphone, and notifications. The source bundle does not provide a CVSS score, impact detail, or exploit evidence, so urgency depends on whether legacy desktop clients remain deployed.

Executive priority

Treat this as an endpoint hygiene and privacy-permission risk until proven otherwise. Prioritize confirmation of installed client versions, especially in environments where Mattermost desktop use is widespread or unmanaged.

Technical view

The flaw concerns Same Origin Policy handling in setPermissionRequestHandler for Mattermost Desktop App before 4.0.0. Permission decisions for video, audio, and notifications may not have been correctly bound to origin. The available sources do not describe prerequisites, attacker control, or the exact security boundary failure.

Likely exposure

Exposure is most likely limited to endpoints running Mattermost Desktop App versions earlier than 4.0.0. The bundle does not identify affected server versions, mobile apps, cloud service exposure, or specific operating systems.

Exploitation context

The CVE is not listed as KEV in the provided bundle, and no cited source states active exploitation. Public source detail is sparse, with no exploit status, proof-of-concept status, or attacker workflow provided.

Researcher notes

Available evidence is limited to the CVE description and Mattermost security reference. Do not assume server-side exposure or active exploitation. The key research question is whether permission prompts could be misattributed across origins in vulnerable desktop clients.

Mitigation direction

  • Inventory Mattermost Desktop App versions across managed endpoints.
  • Move users off Mattermost Desktop App versions before 4.0.0.
  • Check Mattermost security updates for supported fixed client guidance.
  • Remove legacy installers from software portals and device management systems.
  • Prioritize users with camera, microphone, or notification permissions enabled.

Validation and detection

  • Confirm endpoint inventory shows no Mattermost Desktop App below 4.0.0.
  • Review software deployment policies for blocked legacy Mattermost versions.
  • Check whether vulnerable clients remain on unmanaged or BYOD endpoints.
  • Verify helpdesk and self-service portals only offer supported builds.
  • Document any exception owners, timelines, and compensating controls.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-21265 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.