An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creation of a trusted OAuth application does not always require admin privileges, aka MMSA-2020-0001.
{ "cpes": [ "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*", "cpe:2.3:a:mattermost:mattermost_server:5.19.0:rc1:*:*:*:*:*:*", "cpe:2.3:a:mattermost:mattermost_server:5.19.0:rc2:*:*:*:*:*:*", "cpe:2.3:a:mattermost:mattermost_server:5.19.0:rc3:*:*:*:*:*:*" ], "severity": "Medium" }