VYPR

apk package

chainguard/mattermost-fips-10.6-compat

pkg:apk/chainguard/mattermost-fips-10.6-compat

Vulnerabilities (65)

  • CVE-2023-43754MedNov 27, 2023
    affected < 0fixed 0

    Mattermost fails to check whether the  “Allow users to view archived channels”  setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if the “Allow users to view archived channels” setting is disabled. 

  • CVE-2023-40703MedNov 27, 2023
    affected < 0fixed 0

    Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a attacker to consume excessive resources, possibly leading to Denial of Service, by patching the field of a block using a specially crafted string. 

  • CVE-2023-35075LowNov 27, 2023
    affected < 0fixed 0

    Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though. 

  • CVE-2023-47865MedNov 27, 2023
    affected < 0fixed 0

    Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a pos

  • CVE-2022-31022MedJun 1, 2022
    affected < 10.6.3-r2fixed 10.6.3-r2

    Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitation of a node’s filesystem where the bleve index resides, if the user has used bleve’s own HTTP (blev

Page 4 of 4