PT-2020-14018 · Mattermost · Mattermost Server

CVE-2020-14458

·

Published

2020-06-19

·

Updated

2024-03-06

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost Server versions prior to 5.19.0
Description An issue allows attackers to discover private channels via the "get channel by name" API endpoint.
Recommendations For versions prior to 5.19.0, update to version 5.19.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the "get channel by name" API endpoint until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-MATTERMOST-2020-14458
CVE-2020-14458

Affected Products

Mattermost Server