CVE-2019-20877: Medium severity mattermost vulnerability
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-20877?
CVE-2019-20877 is considered to have a medium severity level as it allows attackers to infer sensitive information about user 2FA status.
How do I fix CVE-2019-20877?
To fix CVE-2019-20877, upgrade Mattermost Server to version 5.9.0 or later, or to the respective patched version in the affected release range.
What versions of Mattermost Server are affected by CVE-2019-20877?
CVE-2019-20877 affects Mattermost Server versions before 5.9.0, 5.8.1, 5.7.3, and 4.10.8.
Can I safely use Mattermost Server versions below 5.9.0 with CVE-2019-20877?
No, it is recommended to avoid using affected versions of Mattermost Server due to the vulnerability associated with CVE-2019-20877.
Is CVE-2019-20877 publicly known?
Yes, CVE-2019-20877 is a publicly disclosed vulnerability, making it critical for users to update their Mattermost Server installations.