CVE-2019-20855

HIGH

Mattermost Server <5.16.1-5.9.6 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sensitive information (local files) during legacy attachment migration.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://mattermost.com/security-updates/

Scores

CVSS v3 7.5
EPSS 0.0032
EPSS Percentile 55.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (1)
mattermost/mattermost_server < 5.9.6
Published Jun 19, 2020
Tracked Since Feb 18, 2026