PT-2020-14018 · Mattermost · Mattermost Server

Published

2020-06-19

·

Updated

2024-03-06

·

CVE-2020-14458

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost Server versions prior to 5.19.0
Description An issue allows attackers to discover private channels via the "get channel by name" API endpoint.
Recommendations For versions prior to 5.19.0, update to version 5.19.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the "get channel by name" API endpoint until a patch is available.

Fix

Related Identifiers

BIT-MATTERMOST-2020-14458
CVE-2020-14458

Affected Products

Mattermost Server