CVE-2019-20878
- EPSS 0.23%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:39:35
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled.
CVE-2019-20879
- EPSS 0.15%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:39:36
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry.
CVE-2019-20880
- EPSS 0.39%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:39:36
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph.
CVE-2019-20881
- EPSS 0.28%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:39:36
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
CVE-2019-20882
- EPSS 0.2%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:39:36
An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.
CVE-2019-20883
- EPSS 0.23%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:39:36
An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Users can pin or unpin a post.
CVE-2019-20884
- EPSS 0.24%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:39:36
An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post.
CVE-2019-20885
- EPSS 0.28%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:39:36
An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file.
CVE-2019-20886
- EPSS 0.2%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:39:37
An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.
CVE-2019-20887
- EPSS 0.11%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:39:37
An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts.