Vulnerability index

Browse CVEs

381 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mattermost Server HIGH 8.1
CVE-2017-18894

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner au…

Fix: 4.0.5 / 4.1.1+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18879

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the author_link field of a Slack attachment.

Fix: 4.1.2 / 4.2.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18880

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of a Slack attachment.

Fix: 4.1.2 / 4.2.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18881

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command.

Fix: 4.1.2 / 4.2.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18882

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data.

Fix: 4.1.2 / 4.2.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18891

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.

Fix: 4.0.5 / 4.1.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18892

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutraliz…

Fix: 4.0.5 / 4.1.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.1
CVE-2017-18893

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.

Fix: 4.0.5 / 4.1.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18887

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.

Fix: 4.1.2 / 4.2.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 6.5
CVE-2017-18874

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve director…

Fix: 4.1.2 / 4.2.1+
Fix from $1,600 2020-06-19
Mattermost Server HIGH 8.8
CVE-2018-21264

An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response.

Fix: 4.5.2 / 4.6.2+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18873

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) …

Fix: 4.1.2 / 4.2.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2019-20889

An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation.

Fix: 4.10.5 / 5.5.2+
Fix from $1,600 2020-06-19
Mattermost Server HIGH 8.8
CVE-2018-21263

An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a craft…

Fix: 4.5.2 / 4.6.2+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2018-21262

An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX tex…

Fix: 4.7.3+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2019-20880

An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consump…

Fix: 4.10.7 / 5.6.5+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2019-20885

An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file.

Fix: 5.8.0+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2019-20886

An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.

Fix: 5.8.0+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2019-20888

An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumpti…

Fix: 4.10.5 / 5.5.2+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.3
CVE-2019-20881

An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.

Fix: 5.8.0+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 5.4
CVE-2019-20876

An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.

Fix: 4.10.8 / 5.7.3+
Fix from $1,600 2020-06-19
Mattermost Desktop MEDIUM 5.3
CVE-2018-21265

An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, au…

Fix: 4.0.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2019-20875

An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is…

Fix: 4.10.8 / 5.7.3+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2019-20877

An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whethe…

Fix: 4.10.8 / 5.7.3+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2019-20882

An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.

Fix: 5.8.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2019-20884

An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post.

Fix: 5.8.0+
Fix from $1,600 2020-06-19
Mattermost Server CRITICAL 9.8
CVE-2018-21251

An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the param…

Fix: 5.1.1+
Fix from $2,300 2020-06-19
Mattermost Server HIGH 7.5
CVE-2018-21248

An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials.

Fix: 5.4.0+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2018-21258

An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.

Fix: 5.1.0+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 6.5
CVE-2018-21250

An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consump…

Fix: 4.10.4 / 5.1.2+
Fix from $1,600 2020-06-19