CVE-2019-20859: High severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input.
Affected Software
7 affected components
Mattermost Mattermost Server<4.10.8
Mattermost Mattermost Server>=5.7.0<5.7.3
Mattermost Mattermost Server>=5.8.0<5.8.1
Mattermost Mattermost Server=5.9.0-rc1
Mattermost Mattermost Server=5.9.0-rc2
Mattermost Mattermost Server=5.9.0-rc3
Mattermost Mattermost Server=5.9.0-rc4
Event History
Jun 19, 2020
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20859?
CVE-2019-20859 has been categorized as a high severity vulnerability due to its ability to bypass login access control.
2
How do I fix CVE-2019-20859?
To fix CVE-2019-20859, you should upgrade Mattermost Server to version 5.15.0 or later.
3
What versions of Mattermost Server are affected by CVE-2019-20859?
Mattermost Server versions before 5.15.0, specifically 4.10.8 and 5.7.0 to 5.8.1, are affected by CVE-2019-20859.
4
What type of vulnerability is CVE-2019-20859?
CVE-2019-20859 is a login access control vulnerability that can be exploited through crafted input.
5
Is there a workaround for CVE-2019-20859?
There are no documented workarounds for CVE-2019-20859; upgrading to the latest version is the recommended action.