CVE-2019-20868: Input Validation
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.
Affected Software
7 affected components
Mattermost Mattermost Server<4.10.8
Mattermost Mattermost Server>=5.7.0<5.7.3
Mattermost Mattermost Server>=5.8.0<5.8.1
Mattermost Mattermost Server=5.9.0-rc1
Mattermost Mattermost Server=5.9.0-rc2
Mattermost Mattermost Server=5.9.0-rc3
Mattermost Mattermost Server=5.9.0-rc4
Event History
Jun 19, 2020
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20868?
CVE-2019-20868 has been rated as a moderate severity vulnerability due to improper generation of Invite IDs.
2
How do I fix CVE-2019-20868?
To fix CVE-2019-20868, you should upgrade Mattermost Server to version 5.11.0 or later.
3
Which versions of Mattermost Server are affected by CVE-2019-20868?
CVE-2019-20868 affects Mattermost Server versions prior to 5.11.0, including versions 4.10.8 and certain 5.7.x and 5.8.x versions.
4
What impact does CVE-2019-20868 have on Mattermost Server?
CVE-2019-20868 can potentially allow unauthorized access through improperly generated Invite IDs.
5
Is there a workaround for CVE-2019-20868 if I cannot upgrade?
There are no known workarounds for CVE-2019-20868, so upgrading to a fixed version is recommended.