An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a direct-message channel by changing the type of a channel.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-20844.json"