Input validation error in Mattermost Server - CVE-2019-20871

 

Input validation error in Mattermost Server - CVE-2019-20871

Published: June 19, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34235
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20871
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastrophic backtracking.


Affected software

Mattermost Server

How to mitigate CVE-2019-20871

Install update from vendor's website.

Mattermost Server - update to 5.8.1

External References

Related Security Bulletins