CVE-2019-20842: SQL Injection
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by admins via SearchAllChannels.
Affected Software
8 affected components
Mattermost Mattermost Server<5.9.7
Mattermost Mattermost Server>=5.15.0<5.15.4
Mattermost Mattermost Server>=5.16.0<5.16.4
Mattermost Mattermost Server>=5.17.0<5.17.2
Mattermost Mattermost Server=5.18.0-rc1
Mattermost Mattermost Server=5.18.0-rc2
Mattermost Mattermost Server=5.18.0-rc3
Mattermost Mattermost Server=5.18.0-rc4
Event History
Jun 19, 2020
CVE Published
via MITRE·01:18 PM
Data Sourced
via MITRE·01:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20842?
CVE-2019-20842 is rated as a critical vulnerability due to potential unauthorized SQL injection by admin users.
2
How do I fix CVE-2019-20842?
To mitigate CVE-2019-20842, update Mattermost Server to version 5.18.0 or above.
3
Who is affected by CVE-2019-20842?
CVE-2019-20842 affects Mattermost Server versions before 5.18.0, including various versions in the 5.9.x to 5.17.x range.
4
What types of attacks can CVE-2019-20842 facilitate?
CVE-2019-20842 can allow attackers with admin access to perform SQL injection attacks through the SearchAllChannels functionality.
5
When was CVE-2019-20842 disclosed?
CVE-2019-20842 was disclosed in December 2019 alongside the release of patches for the affected versions.