First published: Fri Jun 19 2020(Updated: )
An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sensitive information (local files) during legacy attachment migration.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost | <5.9.6 | |
Mattermost | >=5.14.0<5.14.5 | |
Mattermost | >=5.15.0<5.15.2 | |
Mattermost | >=5.16.0<5.16.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20855 is rated as a medium severity vulnerability.
To fix CVE-2019-20855, upgrade your Mattermost Server to version 5.16.1 or later.
CVE-2019-20855 allows attackers to obtain sensitive local files during legacy attachment migration.
CVE-2019-20855 affects Mattermost Server versions before 5.9.6, 5.14.5, 5.15.2, and 5.16.1.
Yes, CVE-2019-20855 specifically involves issues during the legacy attachment migration process.