CVE-2020-14460: Medium severity mattermost vulnerability
An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creation of a trusted OAuth application does not always require admin privileges, aka MMSA-2020-0001.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14460?
CVE-2020-14460 has a medium severity level due to its potential impact on admin privileges.
How do I fix CVE-2020-14460?
To fix CVE-2020-14460, upgrade Mattermost Server to version 5.19.0 or later, or apply the relevant security patch.
What versions of Mattermost Server are affected by CVE-2020-14460?
Mattermost Server versions before 5.19.0, including 5.18.1, 5.17.3, 5.16.5, and 5.9.8, are affected by CVE-2020-14460.
Can CVE-2020-14460 allow a non-admin user to create OAuth applications?
Yes, CVE-2020-14460 allows non-admin users to create trusted OAuth applications under certain conditions.
What does it mean for an OAuth application to be trusted in the context of CVE-2020-14460?
A trusted OAuth application can access user data and perform actions without explicit user consent, making it critical to secure.