First published: Fri Jun 19 2020(Updated: )
An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cause a denial of service (application hang) via a crafted SVG document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost | <5.9.4 | |
Mattermost | >=5.12.0<5.12.6 | |
Mattermost | >=5.13.0<5.13.3 | |
Mattermost | =5.14.0-rc1 | |
Mattermost | =5.14.0-rc2 | |
Mattermost | =5.14.0-rc3 | |
Mattermost | =5.14.0-rc4 | |
Mattermost | =5.14.0-rc5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20860 is classified as a denial of service vulnerability that can cause an application hang.
To fix CVE-2019-20860, upgrade Mattermost Server to version 5.14.0 or later.
Mattermost Server versions prior to 5.14.0, 5.13.3, 5.12.6, and 5.9.4 are affected by CVE-2019-20860.
Yes, CVE-2019-20860 can be exploited by remote attackers using a crafted SVG document.
CVE-2019-20860 enables a denial of service attack resulting in application instability.