Skip to main content

Vendor archive

mattermost CVEs

Beta · best-effort

602 CVEs tagged to vendor mattermost21 Critical, 88 High, 367 Medium, 126 Low, 0 Unrated.

CVE-2023-5969

Published Nov 6, 2023

Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5968

Published Nov 6, 2023

Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5967

Published Nov 6, 2023

Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5876

Published Nov 2, 2023

Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-5875

Published Nov 2, 2023

Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-5522

Published Oct 17, 2023

Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5339

Published Oct 17, 2023

Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5333

Published Oct 9, 2023

Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5331

Published Oct 9, 2023

Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exposing unauthorized file information.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5330

Published Oct 9, 2023

Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5160

Published Oct 2, 2023

Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5196

Published Sep 29, 2023

Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server co…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5195

Published Sep 29, 2023

Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5194

Published Sep 29, 2023

Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-5193

Published Sep 29, 2023

Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5159

Published Sep 29, 2023

Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user edit permissions to manage/update bots.

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-4478

Published Aug 25, 2023

Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later acc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4108

Published Aug 11, 2023

Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4107

Published Aug 11, 2023

Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4106

Published Aug 11, 2023

Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and a…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4105

Published Aug 11, 2023

Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-3615

Published Jul 17, 2023

Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3614

Published Jul 17, 2023

Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server resources, making the server unresponsive for an extended pe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3613

Published Jul 17, 2023

Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowing guest accounts to be added or invited to channels by def…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 351-375 of 602 CVEsPage 15 of 25