Mattermost
by Mattermost
Source repositories
CVEs (594)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-54083 | Med | 0.35 | 6.5 | 0.01 | Dec 16, 2024 | Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a specially crafted post. | ||
| CVE-2024-42406 | Med | 0.35 | 5.4 | 0.00 | Sep 26, 2024 | Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged… | ||
| CVE-2023-2000 | Med | 0.35 | 5.4 | 0.00 | May 2, 2023 | Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website | ||
| CVE-2022-0903 | Med | 0.35 | 5.3 | 0.01 | Mar 10, 2022 | A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body. | ||
| CVE-2017-18919 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation. | ||
| CVE-2017-18914 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allowlist. | ||
| CVE-2016-11078 | Med | 0.35 | 6.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI. | ||
| CVE-2016-11072 | Med | 0.35 | 6.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled. | ||
| CVE-2017-18902 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints. | ||
| CVE-2017-18899 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting. | ||
| CVE-2017-18887 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members. | ||
| CVE-2017-18874 | Med | 0.35 | 6.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal. | ||
| CVE-2019-20884 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post. | ||
| CVE-2019-20882 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team. | ||
| CVE-2019-20877 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled. | ||
| CVE-2019-20876 | Med | 0.35 | 5.4 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy. | ||
| CVE-2019-20875 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed. | ||
| CVE-2018-21259 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel. | ||
| CVE-2018-21257 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API. | ||
| CVE-2020-14452 | Med | 0.35 | 5.3 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014. |
- risk 0.35cvss 6.5epss 0.01
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a specially crafted post.
- risk 0.35cvss 5.4epss 0.00
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged…
- risk 0.35cvss 5.4epss 0.00
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
- risk 0.35cvss 5.3epss 0.01
A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allowlist.
- risk 0.35cvss 6.5epss 0.01
An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI.
- risk 0.35cvss 6.5epss 0.01
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.
- risk 0.35cvss 6.5epss 0.01
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014.
Page 10 of 30