Skip to main content

Vendor/product archive

mattermost / mattermost_server CVEs

Beta · best-effort

452 CVEs tagged to mattermost / mattermost_server17 Critical, 63 High, 283 Medium, 89 Low, 0 Unrated.

CVE-2023-3614

Published Jul 17, 2023

Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server resources, making the server unresponsive for an extended pe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3613

Published Jul 17, 2023

Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowing guest accounts to be added or invited to channels by def…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-3593

Published Jul 17, 2023

Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3587

Published Jul 17, 2023

Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any user with a valid sharing link to join the board with editor…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-3586

Published Jul 17, 2023

Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared public Boards to remain access…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3585

Published Jul 17, 2023

Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3584

Published Jul 17, 2023

Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the request, allowing an authenticated attacker with knowledge…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-3582

Published Jul 17, 2023

Mattermost fails to verify channel membership when linking a board to a channel allowing a low-privileged authenticated user to link a Board to a private channel they don't have a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3581

Published Jul 17, 2023

Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3577

Published Jul 17, 2023

Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an attacker to perform a limited blind SSRF.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-2515

Published May 12, 2023

Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2281

Published Apr 25, 2023

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, descrip…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-1831

Published Apr 17, 2023

Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration wa…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1777

Published Mar 31, 2023

Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1776

Published Mar 31, 2023

Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1775

Published Mar 31, 2023

When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1774

Published Mar 31, 2023

When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1421

Published Mar 15, 2023

A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-27266

Published Feb 27, 2023

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-27265

Published Feb 27, 2023

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-3257

Published Sep 23, 2022

Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to c…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-3147

Published Sep 9, 2022

Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhau…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-2401

Published Jul 14, 2022

Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 452 CVEsPage 12 of 19