-
Notifications
You must be signed in to change notification settings - Fork 70
Closed
Labels
excluded: EFFECTIVELY_PRIVATEThis vulnerability exists in a package can be imported, but isn't meant to be outside that module.This vulnerability exists in a package can be imported, but isn't meant to be outside that module.
Description
In GitHub Security Advisory GHSA-j2h2-cvwh-cr64, there is a vulnerability in the following Go packages or modules:
Unit | Fixed | Vulnerable Ranges |
---|---|---|
github.com/mattermost/mattermost | 5.20.0 | < 5.20.0 |
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/mattermost/mattermost
versions:
- fixed: 5.20.0
vulnerable_at: 5.11.1+incompatible
packages:
- package: github.com/mattermost/mattermost
summary: Mattermost Server Sensitive Data Exposure
description: |-
An issue was discovered in Mattermost Server before 5.20.0. Non-members can
receive broadcasted team details via the `update_team` WebSocket event, aka
MMSA-2020-0012.
cves:
- CVE-2020-14457
ghsas:
- GHSA-j2h2-cvwh-cr64
references:
- web: https://nvd.nist.gov/vuln/detail/CVE-2020-14457
- web: https://mattermost.com/security-updates/
- fix: https://github.com/mattermost/mattermost/pull/13848
- advisory: https://github.com/advisories/GHSA-j2h2-cvwh-cr64
Metadata
Metadata
Assignees
Labels
excluded: EFFECTIVELY_PRIVATEThis vulnerability exists in a package can be imported, but isn't meant to be outside that module.This vulnerability exists in a package can be imported, but isn't meant to be outside that module.