CVE-2019-20880: High severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph.
Affected Software
7 affected components
Mattermost Mattermost Server<4.10.7
Mattermost Mattermost Server>=5.6.0<5.6.5
Mattermost Mattermost Server>=5.7.0<5.7.2
Mattermost Mattermost Server=5.8.0-rc1
Mattermost Mattermost Server=5.8.0-rc2
Mattermost Mattermost Server=5.8.0-rc3
Mattermost Mattermost Server=5.8.0-rc4
Event History
Jun 19, 2020
CVE Published
via MITRE·04:29 PM
Data Sourced
via MITRE·04:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20880?
The severity of CVE-2019-20880 is categorized as a denial of service vulnerability.
2
How do I fix CVE-2019-20880?
To fix CVE-2019-20880, upgrade Mattermost Server to version 5.8.0 or later.
3
What versions of Mattermost Server are affected by CVE-2019-20880?
Versions of Mattermost Server prior to 5.8.0, as well as 5.7.2, 5.6.5, and 4.10.7, are affected by CVE-2019-20880.
4
What type of attack is possible with CVE-2019-20880?
CVE-2019-20880 allows attackers to perform a denial of service attack that leads to memory consumption.
5
Is there a patch available for CVE-2019-20880?
Yes, a patch is included in versions 5.8.0 and newer of Mattermost Server.