VYPR

apk package

chainguard/mattermost-fips-10.5-compat

pkg:apk/chainguard/mattermost-fips-10.5-compat

Vulnerabilities (63)

  • CVE-2023-35075LowNov 27, 2023
    affected < 0fixed 0

    Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though. 

  • CVE-2023-47865MedNov 27, 2023
    affected < 0fixed 0

    Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a pos

  • CVE-2022-31022MedJun 1, 2022
    affected < 10.5.5-r1fixed 10.5.5-r1

    Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitation of a node’s filesystem where the bleve index resides, if the user has used bleve’s own HTTP (blev

Page 4 of 4