Skip to main content

Vendor/product archive

mattermost / mattermost_server CVEs

Beta · best-effort

452 CVEs tagged to mattermost / mattermost_server17 Critical, 63 High, 283 Medium, 89 Low, 0 Unrated.

CVE-2024-11599

Published Nov 28, 2024

Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52032

Published Nov 9, 2024

Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42000

Published Nov 9, 2024

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels  which allows a User or Sys…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-36250

Published Nov 9, 2024

Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-47401

Published Oct 29, 2024

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to gen…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46872

Published Oct 29, 2024

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click clie…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50052

Published Oct 29, 2024

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10241

Published Oct 29, 2024

Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9155

Published Sep 26, 2024

Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have not been linked to a post which allows an attacker to view th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47145

Published Sep 26, 2024

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and fi…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-47003

Published Sep 26, 2024

Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker to send a non-string value as…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-45843

Published Sep 26, 2024

Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if M…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42406

Published Sep 26, 2024

Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which all…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43780

Published Aug 22, 2024

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42497

Published Aug 22, 2024

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems manager role with read-o…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40884

Published Aug 22, 2024

Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invit…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-41926

Published Aug 1, 2024

Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set ar…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-41162

Published Aug 1, 2024

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are ena…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41144

Published Aug 1, 2024

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled,  which allows a malici…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39839

Published Aug 1, 2024

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, whic…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39837

Published Aug 1, 2024

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels we…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-5272

Published May 26, 2024

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a gues…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5270

Published May 26, 2024

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is enabled when a user requests to sw…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36255

Published May 26, 2024

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36241

Published May 26, 2024

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook a…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort
Showing 201-225 of 452 CVEsPage 9 of 19