Mattermost
by Mattermost
Source repositories
CVEs (566)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2193 | Med | 0.42 | 6.5 | 0.01 | Apr 20, 2023 | Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token. | ||
| CVE-2023-1777 | Med | 0.42 | 6.5 | 0.01 | Mar 31, 2023 | Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message. | ||
| CVE-2022-2401 | Med | 0.42 | 6.5 | 0.01 | Jul 14, 2022 | Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs. | ||
| CVE-2017-18917 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens. | ||
| CVE-2016-11069 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change. | ||
| CVE-2016-11066 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information. | ||
| CVE-2017-18909 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory. | ||
| CVE-2019-20888 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumption) via an outgoing webhook or a slash command integration. | ||
| CVE-2018-21258 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command. | ||
| CVE-2018-21250 | Med | 0.42 | 6.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consumption) via crafted image dimensions. | ||
| CVE-2019-20873 | Med | 0.42 | 6.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during user activation/deactivation. | ||
| CVE-2019-20868 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated. | ||
| CVE-2019-20863 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted. | ||
| CVE-2019-20862 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands. | ||
| CVE-2019-20859 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input. | ||
| CVE-2019-20858 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consumption) via crafted characters in a SQL LIKE clause to an APIv4 endpoint. | ||
| CVE-2019-20857 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of service (markdown renderer hang) via many backtick characters. | ||
| CVE-2019-20855 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sensitive information (local files) during legacy attachment migration. | ||
| CVE-2019-20854 | Hig | 0.42 | 7.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a denial of service (client-side application crash) via a LaTeX message. | ||
| CVE-2020-14460 | Med | 0.42 | 6.5 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creation of a trusted OAuth application does not always require admin privileges, aka MMSA-2020-0001. |
- risk 0.42cvss 6.5epss 0.01
Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token.
- risk 0.42cvss 6.5epss 0.01
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
- risk 0.42cvss 6.5epss 0.01
Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumption) via an outgoing webhook or a slash command integration.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consumption) via crafted image dimensions.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during user activation/deactivation.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consumption) via crafted characters in a SQL LIKE clause to an APIv4 endpoint.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of service (markdown renderer hang) via many backtick characters.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sensitive information (local files) during legacy attachment migration.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a denial of service (client-side application crash) via a LaTeX message.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creation of a trusted OAuth application does not always require admin privileges, aka MMSA-2020-0001.
Page 6 of 29