CVE-2019-20875: Medium severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.
Affected Software
7 affected components
Mattermost Mattermost Server<4.10.8
Mattermost Mattermost Server>=5.7.0<5.7.3
Mattermost Mattermost Server>=5.8.0<5.8.1
Mattermost Mattermost Server=5.9.0-rc1
Mattermost Mattermost Server=5.9.0-rc2
Mattermost Mattermost Server=5.9.0-rc3
Mattermost Mattermost Server=5.9.0-rc4
Event History
Jun 19, 2020
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20875?
CVE-2019-20875 is classified as a high-severity vulnerability due to its impact on password reset functionality.
2
How do I fix CVE-2019-20875?
To remediate CVE-2019-20875, upgrade to Mattermost Server version 5.9.0 or later.
3
What component is affected by CVE-2019-20875?
CVE-2019-20875 affects the Mattermost Server application, specifically versions prior to 5.9.0.
4
Can CVE-2019-20875 lead to unauthorized access?
Yes, CVE-2019-20875 can potentially allow unauthorized password resets while an email address is being changed.
5
Are there any workarounds for CVE-2019-20875?
There are no specific workarounds for CVE-2019-20875; the best option is to update to a secure version.