CVE-2019-20872: SSRF
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.
Affected Software
7 affected components
Mattermost Mattermost Server<4.10.8
Mattermost Mattermost Server>=5.7.0<5.7.3
Mattermost Mattermost Server>=5.8.0<5.8.1
Mattermost Mattermost Server=5.9.0-rc1
Mattermost Mattermost Server=5.9.0-rc2
Mattermost Mattermost Server=5.9.0-rc3
Mattermost Mattermost Server=5.9.0-rc4
Event History
Jun 19, 2020
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20872?
CVE-2019-20872 is classified as a medium severity vulnerability due to the potential for SSRF attacks against local services.
2
How do I fix CVE-2019-20872?
To fix CVE-2019-20872, upgrade to Mattermost Server version 5.9.0 or later, or apply the applicable patches.
3
What systems are affected by CVE-2019-20872?
CVE-2019-20872 affects Mattermost Server versions prior to 5.9.0, along with various earlier versions of 5.8, 5.7, and 4.10.
4
What does SSRF mean in the context of CVE-2019-20872?
SSRF stands for Server-Side Request Forgery, which is a type of attack that allows an attacker to send crafted requests from a vulnerable server.
5
Are there any workarounds for CVE-2019-20872?
There are no specific workarounds for CVE-2019-20872 other than upgrading to a fixed version of Mattermost Server.