VYPR

Mattermost

by Mattermost

Source repositories

CVEs (566)

  • CVE-2024-36250LowNov 9, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds

  • CVE-2024-47145LowSep 26, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.

  • CVE-2024-45843LowSep 26, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.

  • CVE-2024-41162MedAug 1, 2024
    risk 0.20cvss 4.1epss 0.00

    Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only.

  • CVE-2024-39767MedJul 15, 2024
    risk 0.20cvss 4.2epss 0.00

    Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in…

  • CVE-2024-36241LowMay 26, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook add slash command

  • CVE-2024-3872LowApr 16, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.

  • CVE-2024-21848LowApr 5, 2024
    risk 0.20cvss 3.1epss 0.00

    Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel

  • CVE-2024-1952LowFeb 29, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member…

  • CVE-2024-23488LowFeb 29, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members being able to access files of archived channels even if the “Allow users to view archived channels” option is disabled.

  • CVE-2024-24776LowFeb 9, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.

  • CVE-2023-6727LowDec 12, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access to the playbook to create playbook actions. If the playbook action created is to post a message in a channel based on specific keywords in a post, some…

  • CVE-2023-35075LowNov 27, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though. 

  • CVE-2023-5876LowNov 2, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.

  • CVE-2023-4105LowAug 11, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message

  • CVE-2023-3590LowJul 17, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.

  • CVE-2023-3584LowJul 17, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the request, allowing an authenticated attacker with knowledge of a Team Override Scheme ID to create a new team with said team override scheme.

  • CVE-2023-2797LowJun 16, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink on a channel.

  • CVE-2023-2281LowApr 25, 2023
    risk 0.20cvss 3.1epss 0.00

    When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

  • CVE-2022-4045LowNov 23, 2022
    risk 0.20cvss 3.1epss 0.01

    A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data. 

Page 24 of 29