CVE Vulnerabilities

CVE-2019-20886

Improper Privilege Management

Published: Jun 19, 2020 | Modified: Jun 23, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Mattermost_server Mattermost * 5.8.0 (excluding)

Potential Mitigations

References