VYPR

Playbook Plugin

by Mattermost

CVEs (4)

  • CVE-2023-46701MedDec 12, 2023
    risk 0.42cvss 6.5epss 0.00

    Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allowing an attacker to get limited information about a post if they know the post ID

  • CVE-2023-49607MedDec 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker to crash the Playbook Plugin when updating the status dialog.

  • CVE-2022-4019MedNov 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.

  • CVE-2022-1548LowMay 3, 2022
    risk 0.24cvss 3.7epss 0.01

    Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membership privileges and perform actions restricted to playbook admins.