VYPR

apk package

chainguard/mattermost-fips-10.6-compat

pkg:apk/chainguard/mattermost-fips-10.6-compat

Vulnerabilities (65)

  • CVE-2023-40703Nov 27, 2023
    affected < 0fixed 0

    Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a attacker to consume excessive resources, possibly leading to Denial of Service, by patching the field of a block using a specially crafted string. 

  • CVE-2023-48268Nov 27, 2023
    affected < 0fixed 0

    Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).

  • CVE-2023-45223Nov 27, 2023
    affected < 0fixed 0

    Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a member to get the full name of another user even if the Show Full Name option was disabled. 

  • CVE-2023-47865Nov 27, 2023
    affected < 0fixed 0

    Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a pos

  • CVE-2022-31022Jun 1, 2022
    affected < 10.6.3-r2fixed 10.6.3-r2

    Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitation of a node’s filesystem where the bleve index resides, if the user has used bleve’s own HTTP (blev

Page 4 of 4