CVE Vulnerabilities

CVE-2019-20843

Improper Preservation of Permissions

Published: Jun 19, 2020 | Modified: Jun 19, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permissions for configuration files.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

Name Vendor Start Version End Version
Mattermost_server Mattermost * 5.9.7 (excluding)
Mattermost_server Mattermost 5.15.0 (including) 5.15.4 (excluding)
Mattermost_server Mattermost 5.16.0 (including) 5.16.4 (excluding)
Mattermost_server Mattermost 5.17.0 (including) 5.17.2 (excluding)
Mattermost_server Mattermost 5.18.0-rc1 (including) 5.18.0-rc1 (including)
Mattermost_server Mattermost 5.18.0-rc2 (including) 5.18.0-rc2 (including)
Mattermost_server Mattermost 5.18.0-rc3 (including) 5.18.0-rc3 (including)
Mattermost_server Mattermost 5.18.0-rc4 (including) 5.18.0-rc4 (including)

References