Vulnerability index

Browse CVEs

379 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mattermost MEDIUM 5.3
CVE-2024-39807

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook …

Fix: 9.5.6 / 9.8.1+
Fix from $1,600 2024-07-03
Mattermost MEDIUM 5.4
CVE-2024-39361

Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which a…

Fix: 9.5.6 / 9.6.3+
Fix from $1,600 2024-07-03
Mattermost MEDIUM 5.3
CVE-2024-36257

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server…

Fix: 9.5.6+
Fix from $1,600 2024-07-03
Mattermost Desktop MEDIUM 6.1
CVE-2024-37182

Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a …

Fix: after 5.7.0
Fix from $1,600 2024-06-14
Mattermost Server MEDIUM 5.7
CVE-2024-36255

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attack…

Fix: 8.1.13 / 9.5.4+
Fix from $1,600 2024-05-26
Mattermost Server MEDIUM 5.9
CVE-2024-32045

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linki…

Fix: 8.1.13 / 9.5.4+
Fix from $1,600 2024-05-26
Mattermost Server MEDIUM 6.3
CVE-2024-31859

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a pl…

Fix: 8.1.13 / 9.5.4+
Fix from $1,600 2024-05-26
Mattermost Server MEDIUM 6.5
CVE-2024-4183

Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, whic…

Fix: 8.1.12 / 9.4.5+
Fix from $1,600 2024-04-26
Mattermost Server MEDIUM 6.5
CVE-2024-22091

Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user i…

Fix: 8.1.12 / 9.5.3+
Fix from $1,600 2024-04-26
Mattermost Mobile MEDIUM 6.5
CVE-2024-3872

Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an una…

Fix: after 2.13.0
Fix from $1,600 2024-04-16
Mattermost Server MEDIUM 6.5
CVE-2024-28949

Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences…

Fix: 8.1.11 / 9.3.3+
Fix from $1,600 2024-04-05
Mattermost Server MEDIUM 6.5
CVE-2024-2447

Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain ty…

Fix: 8.1.11 / 9.3.3+
Fix from $1,600 2024-04-05
Mattermost Server HIGH 8.8
CVE-2024-2450

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership wh…

Fix: 8.1.10 / 9.2.6+
Fix from $1,950 2024-03-15
Mattermost Server MEDIUM 6.1
CVE-2024-2445

Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 …

Fix: 8.1.10 / 9.2.6+
Fix from $1,600 2024-03-15
Mattermost Server MEDIUM 6.5
CVE-2024-28053

Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an …

Fix: 8.1.10+
Fix from $1,600 2024-03-15
Mattermost Mobile MEDIUM 6.5
CVE-2024-24975

Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the…

Fix: 2.13.0+
Fix from $1,600 2024-03-15
Mattermost Server MEDIUM 6.5
CVE-2024-23493

Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a …

Fix: 8.1.9 / 9.2.5+
Fix from $1,600 2024-02-29
Mattermost Server MEDIUM 6.5
CVE-2024-24988

Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very lon…

Fix: 8.1.8 / 9.1.5+
Fix from $1,600 2024-02-29
Mattermost HIGH 8.8
CVE-2023-7114

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

Fix: 2.10.1+
Fix from $1,950 2023-12-29
Mattermost Server MEDIUM 6.1
CVE-2023-7113

Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.

Fix: 8.1.7+
Fix from $1,600 2023-12-29
Mattermost Server MEDIUM 6.5
CVE-2023-49809

Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with null request body to that endpoi…

Fix: after 9.1.0
Fix from $1,600 2023-12-12
Mattermost Server MEDIUM 5.4
CVE-2023-6547

Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permiss…

Fix: after 9.2.1
Fix from $1,600 2023-12-12
Mattermost Server HIGH 7.5
CVE-2023-49607

Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker to crash the Playbook Plugin when updating the st…

Fix: after 9.2.1
Fix from $1,950 2023-12-12
Mattermost Server MEDIUM 5.3
CVE-2023-46701

Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allow…

Fix: after 9.2.1
Fix from $1,600 2023-12-12
Mattermost Server HIGH 8.8
CVE-2023-45316

Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing a…

Fix: after 9.2.1
Fix from $1,950 2023-12-12
Mattermost Server HIGH 7.5
CVE-2023-45847

Mattermost fails to to check the length when setting the title in a run checklist in Playbooks, allowing an attacker to send a specially crafted requ…

Fix: after 9.2.1
Fix from $1,950 2023-12-12
Mattermost Server MEDIUM 5.3
CVE-2023-6459

Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics …

Fix: 7.8.14 / 8.1.5+
Fix from $1,600 2023-12-06
Mattermost Server CRITICAL 9.8
CVE-2023-6458

Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traver…

Fix: 7.8.14 / 8.1.5+
Fix from $2,300 2023-12-06
Mattermost HIGH 7.5
CVE-2023-48268

Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to cons…

Fix: after 9.0.1
Fix from $1,950 2023-11-27
Mattermost MEDIUM 6.1
CVE-2023-47168

Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" aft…

Fix: after 9.0.1
Fix from $1,600 2023-11-27