An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the “get channel by name” API, aka MMSA-2020-0004.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14458
Reference (s):
- https://mattermost.com/security-updates/

