Vulnerability index

Browse CVEs

381 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mattermost Mobile HIGH 7.5
CVE-2020-14449

An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to third-party servers, aka MMSA-202…

Fix: 1.30.0+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2020-14450

An issue was discovered in Mattermost Server before 5.22.0. The markdown renderer allows attackers to cause a denial of service (client-side), aka MM…

Fix: 5.22.0+
Fix from $1,950 2020-06-19
Mattermost Mobile HIGH 7.5
CVE-2020-14451

An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local Storage to remain after a logou…

Fix: 1.29.0+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2020-14453

An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, which allows attackers to cause …

Fix: 5.21.0+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2020-14458

An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel by name" API, aka MMSA-2020-…

Fix: 5.19.0+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2020-14459

An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a direct message, aka MMSA-2020…

Fix: 5.19.0+
Fix from $1,950 2020-06-19
Mattermost Desktop HIGH 7.3
CVE-2020-14456

An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, ak…

Fix: 4.4.0+
Fix from $1,950 2020-06-19
Mattermost Desktop MEDIUM 6.5
CVE-2020-14455

An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-20…

Fix: 4.4.0+
Fix from $1,600 2020-06-19
Mattermost Desktop MEDIUM 6.1
CVE-2020-14454

An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is…

Fix: 4.4.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2020-14452

An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014.

Fix: 5.21.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2020-14457

An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the update_team WebSocket event, aka…

Fix: 5.20.0+
Fix from $1,600 2020-06-19
Mattermost Server HIGH 8.8
CVE-2019-20841

An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for ac…

Fix: 5.9.7 / 5.15.4+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2019-20843

An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permissions for configuration files.

Fix: 5.9.7 / 5.15.4+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2019-20845

An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory consumption) via a large Slack i…

Fix: 5.18.0+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2019-20846

An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local file storage.

Fix: 5.18.0+
Fix from $1,950 2020-06-19
Mattermost Mobile HIGH 7.5
CVE-2019-20848

An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies.

Fix: 1.26.0+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.2
CVE-2019-20842

An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by admins via SearchAllChannels.

Fix: 5.9.7 / 5.15.4+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 6.5
CVE-2019-20844

An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a direct-message channel by chan…

Fix: 5.9.7 / 5.15.4+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2019-20847

An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any channel.

Fix: 5.18.0+
Fix from $1,600 2020-06-19
Mattermost Mobile MEDIUM 5.3
CVE-2019-20849

An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.

Fix: 1.26.0+
Fix from $1,600 2020-06-19
Mattermost Mobile MEDIUM 5.3
CVE-2019-20850

An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.

Fix: 1.26.0+
Fix from $1,600 2020-06-19