An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Update/Patch Channel endpoint for a private channel.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20869.json"