CVE-2019-20852
published 2020-06-19CVE-2019-20852: An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message…
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.12%
62.4th percentile
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content).
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mattermost | mattermost_mobile | < 1.26.0 | 1.26.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fp87-873p-j338: An issue was discovered in Mattermost Mobile Apps before 1
ghsa_unreviewed·2022-05-24
CVE-2019-20852 [MEDIUM] CWE-200 GHSA-fp87-873p-j338: An issue was discovered in Mattermost Mobile Apps before 1
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content).
OSV
python2.7, python3.5, python3.6, python3.7 vulnerabilities
osv·2019-09-09·CVSS 7.5
CVE-2018-20406 python2.7, python3.5, python3.6, python3.7 vulnerabilities
python2.7, python3.5, python3.6, python3.7 vulnerabilities
It was discovered that Python incorrectly handled certain pickle files. An
attacker could possibly use this issue to consume memory, leading to a
denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2018-20406)
It was discovered that Python incorrectly validated the domain when
handling cookies. An attacker could possibly trick Python into sending
cookies to the wrong domain. (CVE-2018-20852)
Jonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly
handled Unicode encoding during NFKC normalization. An attacker could
possibly use this issue to obtain sensitive information. (CVE-2019-9636,
CVE-2019-10160)
Colin Read and Nicolas Edet discovered that Python incorrectly handled
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-19
Published