CVE-2019-20887: Medium severity mattermost vulnerability
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts.
Affected Software
4 affected components
Mattermost Mattermost Server<4.10.6
Mattermost Mattermost Server>=5.5.0<5.5.3
Mattermost Mattermost Server>=5.6.0<5.6.4
Mattermost Mattermost Server>=5.7.0<5.7.1
Event History
Jun 19, 2020
CVE Published
via MITRE·04:39 PM
Data Sourced
via MITRE·04:39 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20887?
CVE-2019-20887 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2019-20887?
To fix CVE-2019-20887, upgrade Mattermost Server to version 5.7.1, 5.6.4, 5.5.3, or 4.10.6 or later.
3
What does CVE-2019-20887 affect?
CVE-2019-20887 affects Mattermost Server versions prior to 5.7.1, 5.6.4, 5.5.3, and 4.10.6.
4
What type of vulnerability is CVE-2019-20887?
CVE-2019-20887 is a permission handling vulnerability related to intra-team posts.
5
Is CVE-2019-20887 exploited remotely?
CVE-2019-20887 can potentially be exploited by authenticated users within the Mattermost environment.