CVE-2019-20855: High severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sensitive information (local files) during legacy attachment migration.
Affected Software
4 affected components
Mattermost Mattermost Server<5.9.6
Mattermost Mattermost Server>=5.14.0<5.14.5
Mattermost Mattermost Server>=5.15.0<5.15.2
Mattermost Mattermost Server>=5.16.0<5.16.1
Event History
Jun 19, 2020
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20855?
CVE-2019-20855 is rated as a medium severity vulnerability.
2
How do I fix CVE-2019-20855?
To fix CVE-2019-20855, upgrade your Mattermost Server to version 5.16.1 or later.
3
What information can be compromised due to CVE-2019-20855?
CVE-2019-20855 allows attackers to obtain sensitive local files during legacy attachment migration.
4
Which versions of Mattermost Server are affected by CVE-2019-20855?
CVE-2019-20855 affects Mattermost Server versions before 5.9.6, 5.14.5, 5.15.2, and 5.16.1.
5
Is CVE-2019-20855 related to attachment migration?
Yes, CVE-2019-20855 specifically involves issues during the legacy attachment migration process.