Vulnerability index

Browse CVEs

379 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mattermost Server HIGH 8.8
CVE-2023-2515

Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to syst…

Fix: 7.1.8 / 7.7.4+
Fix from $1,950 2023-05-12
Mattermost HIGH 7.5
CVE-2023-2514

Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization. 

Fix: after 7.9.1
Fix from $1,950 2023-05-12
Mattermost Desktop MEDIUM 5.4
CVE-2023-2000

Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website

Fix: after 5.2.2
Fix from $1,600 2023-05-02
Mattermost CRITICAL 9.1
CVE-2023-2193

Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code t…

Mitigation only
Fix from $2,300 2023-04-20
Mattermost Server HIGH 7.5
CVE-2023-1831

Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental …

Fix: 7.7.3 / 7.8.2+
Fix from $1,950 2023-04-17
Mattermost Server MEDIUM 6.5
CVE-2023-1775

When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all use…

Fix: 7.1.6+
Fix from $1,600 2023-03-31
Mattermost Server MEDIUM 5.4
CVE-2023-1774

When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an at…

Fix: 7.1.6+
Fix from $1,600 2023-03-31
Mattermost Server MEDIUM 5.4
CVE-2023-1776

Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.

Fix: 7.1.6+
Fix from $1,600 2023-03-31
Mattermost Server MEDIUM 5.3
CVE-2023-1777

Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the con…

Fix: 7.1.6+
Fix from $1,600 2023-03-31
Mattermost Server MEDIUM 6.1
CVE-2023-1421

A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behal…

Fix: 7.7.0+
Fix from $1,600 2023-03-15
Mattermost MEDIUM 6.5
CVE-2023-27263

A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team…

Fix: after 7.1.4
Fix from $1,600 2023-02-27
Mattermost MEDIUM 6.5
CVE-2023-27264

A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks…

Fix: after 7.1.4
Fix from $1,600 2023-02-27
Mattermost MEDIUM 6.5
CVE-2022-4045

A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoint…

Mitigation only
Fix from $1,600 2022-11-23
Mattermost MEDIUM 6.5
CVE-2022-4019

A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to …

Mitigation only
Fix from $1,600 2022-11-23
Mattermost MEDIUM 6.5
CVE-2022-4044

A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.

Fix: 7.4+
Fix from $1,600 2022-11-23
Mattermost Server MEDIUM 6.5
CVE-2022-3257

Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which a…

Fix: 7.2.0+
Fix from $1,600 2022-09-23
Mattermost Server MEDIUM 6.5
CVE-2022-3147

Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated…

Fix: 7.1.0+
Fix from $1,600 2022-09-09
Mattermost Server MEDIUM 6.5
CVE-2022-2401

Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by …

Fix: 6.3.9 / 6.5.2+
Fix from $1,600 2022-07-14
Mattermost MEDIUM 6.5
CVE-2022-2406

The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenti…

Fix: after 6.5.1
Fix from $1,600 2022-07-14
Mattermost Server MEDIUM 5.3
CVE-2022-2366

Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations …

Fix: 6.3.9 / 6.5.2+
Fix from $1,600 2022-07-12
Mattermost Server MEDIUM 6.5
CVE-2022-1982

Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG atta…

Fix: 6.3.8 / 6.4.3+
Fix from $1,600 2022-06-02
Playbooks HIGH 8.8
CVE-2022-1548

Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membe…

Fix: after 1.25.0
Fix from $1,950 2022-05-03
Mattermost Server HIGH 8.8
CVE-2022-1384

Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an auth…

Fix: 6.5.0+
Fix from $1,950 2022-04-19
Playbooks MEDIUM 6.5
CVE-2022-1333

Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorize…

Fix: after 1.24.0
Fix from $1,600 2022-04-13
Mattermost Server MEDIUM 6.5
CVE-2022-1337

The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authentica…

Fix: 5.37.9 / 6.2.5+
Fix from $1,600 2022-04-13
Mattermost MEDIUM 5.4
CVE-2022-1002

Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users w…

Fix: 6.4.0+
Fix from $1,600 2022-03-18
Mattermost Server HIGH 7.5
CVE-2022-0903

A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server…

Fix: 5.37.8 / 6.1.3+
Fix from $1,950 2022-03-10
Mattermost Server MEDIUM 6.5
CVE-2022-0904

A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via …

Fix: 5.37.8 / 6.1.3+
Fix from $1,600 2022-03-10
Mattermost MEDIUM 6.5
CVE-2022-0708

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members…

Fix: after 6.3.0
Fix from $1,600 2022-02-21
Mattermost Boards HIGH 7.5
CVE-2021-37866

Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attac…

Fix: after 0.10.0
Fix from $1,950 2022-01-18