cbcvebase.
CVE-2019-20874
published 2020-06-19

CVE-2019-20874: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during a role change.

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during a role change.

Affected

4 ranges
VendorProductVersion rangeFixed in
mattermostmattermost_server< 4.10.84.10.8
mattermostmattermost_server
mattermostmattermost_server>= 5.7.0 < 5.7.35.7.3
mattermostmattermost_server>= 5.8.0 < 5.8.15.8.1