CVE-2019-14366: Infoleak
Published Nov 12, 2019
·Updated
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
Affected Software
1 affected component
Slack Wp Slacksync Wordpress<=1.8.5
Event History
Nov 12, 2019
CVE Published
via MITRE·08:47 PM
Data Sourced
via MITRE·08:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14366?
CVE-2019-14366 is considered a high-severity vulnerability due to the potential exposure of sensitive Slack Access Tokens.
2
How do I fix CVE-2019-14366?
To fix CVE-2019-14366, update the WP SlackSync plugin to a version higher than 1.8.5.
3
What information can be leaked due to CVE-2019-14366?
CVE-2019-14366 can leak sensitive information such as Slack channels, members, and other related data.
4
Is CVE-2019-14366 still a risk if I am using a version of the plugin above 1.8.5?
If you are using a version of the WP SlackSync plugin above 1.8.5, CVE-2019-14366 should not be a risk.
5
How does CVE-2019-14366 affect my organization's security?
CVE-2019-14366 poses a risk to your organization's security by potentially allowing attackers to gain unauthorized access to Slack user data.