CVE-2019-20879: Medium severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry.
Affected Software
7 affected components
Mattermost Mattermost Server<4.10.7
Mattermost Mattermost Server>=5.6.0<5.6.5
Mattermost Mattermost Server>=5.7.0<5.7.2
Mattermost Mattermost Server=5.8.0-rc1
Mattermost Mattermost Server=5.8.0-rc2
Mattermost Mattermost Server=5.8.0-rc3
Mattermost Mattermost Server=5.8.0-rc4
Event History
Jun 19, 2020
CVE Published
via MITRE·04:29 PM
Data Sourced
via MITRE·04:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20879?
CVE-2019-20879 has been classified as a moderate severity vulnerability due to the potential risk of unauthorized email changes.
2
How do I fix CVE-2019-20879?
To fix CVE-2019-20879, upgrade Mattermost Server to version 5.8.0 or later.
3
What versions of Mattermost Server are affected by CVE-2019-20879?
CVE-2019-20879 affects Mattermost Server versions prior to 5.8.0, 5.7.2, 5.6.5, and 4.10.7.
4
What are the implications of CVE-2019-20879?
The vulnerability allows users to change email addresses without needing to re-enter credentials, posing a risk to account integrity.
5
Is there a patch available for CVE-2019-20879?
Yes, the patch for CVE-2019-20879 is included in Mattermost Server versions released after 5.8.0.