VendorsMattermostmattermost_server5.9.0
Vulnerabilities

Mattermost Server 5.9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2019-20859
An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input.
Published 2020-06-19 · Modified
7.5EPSS 0.012
CVE-2019-20874
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during a role change.
Published 2020-06-19 · Modified
7.5EPSS 0.012
CVE-2019-20871
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastrophic backtracking.
Published 2020-06-19 · Modified
7.5EPSS 0.011
CVE-2019-20868
An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.
Published 2020-06-19 · Modified
7.5EPSS 0.009
CVE-2019-20873
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during user activation/deactivation.
Published 2020-06-19 · Modified
6.5EPSS 0.009
CVE-2019-20876
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.
Published 2020-06-19 · Modified
5.5EPSS 0.008
CVE-2019-20872
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.
Published 2020-06-19 · Modified
5.5EPSS 0.003
CVE-2019-20877
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.
Published 2020-06-19 · Modified
5.3EPSS 0.009
CVE-2019-20875
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.
Published 2020-06-19 · Modified
5.3EPSS 0.008
CVE-2019-20878
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled.
Published 2020-06-19 · Modified
4.3EPSS 0.007