CVE-2019-20874: High severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during a role change.
Affected Software
7 affected components
Mattermost Mattermost Server<4.10.8
Mattermost Mattermost Server>=5.7.0<5.7.3
Mattermost Mattermost Server>=5.8.0<5.8.1
Mattermost Mattermost Server=5.9.0-rc1
Mattermost Mattermost Server=5.9.0-rc2
Mattermost Mattermost Server=5.9.0-rc3
Mattermost Mattermost Server=5.9.0-rc4
Event History
Jun 19, 2020
CVE Published
via MITRE·03:42 PM
Data Sourced
via MITRE·03:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20874?
CVE-2019-20874 is considered a medium-severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2019-20874?
To fix CVE-2019-20874, upgrade Mattermost Server to version 5.9.0 or later.
3
What versions of Mattermost Server are affected by CVE-2019-20874?
CVE-2019-20874 affects Mattermost Server versions prior to 5.9.0, including 5.8.0, 5.7.x, and 4.10.x.
4
What kind of sensitive information can be exposed due to CVE-2019-20874?
CVE-2019-20874 can expose sensitive user details during role change operations.
5
Is there a workaround for CVE-2019-20874?
There is no formal workaround for CVE-2019-20874; the best mitigation is to apply the available security update.