Skip to main content

Vendor archive

mattermost CVEs

Beta · best-effort

602 CVEs tagged to vendor mattermost21 Critical, 88 High, 367 Medium, 126 Low, 0 Unrated.

CVE-2024-39274

Published Aug 1, 2024

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the sync message is a shared chann…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36492

Published Aug 1, 2024

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing users in shared channels. which al…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29977

Published Aug 1, 2024

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrar…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-39767

Published Jul 15, 2024

Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to s…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32945

Published Jul 15, 2024

Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creat…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-6428

Published Jul 3, 2024

Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39830

Published Jul 3, 2024

Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time comparison for remote cluster to…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39807

Published Jul 3, 2024

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-39361

Published Jul 3, 2024

Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify b…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-39353

Published Jul 3, 2024

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-36257

Published Jul 3, 2024

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-37182

Published Jun 14, 2024

Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to ru…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5272

Published May 26, 2024

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a gues…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5270

Published May 26, 2024

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is enabled when a user requests to sw…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36255

Published May 26, 2024

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36241

Published May 26, 2024

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook a…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-34152

Published May 26, 2024

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allows a guest to get the metadata of a public playbook run that…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34029

Published May 26, 2024

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups/<group-id>/channels/<channel-id>/link end…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32045

Published May 26, 2024

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31859

Published May 26, 2024

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29215

Published May 26, 2024

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access control which allows a user to run a slash command in a channel t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4198

Published Apr 26, 2024

Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-4195

Published Apr 26, 2024

Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guest…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-4183

Published Apr 26, 2024

Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated atta…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 602 CVEsPage 12 of 25