Vulnerability index

Browse CVEs

381 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2017-18894 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner au… Mattermost Server 4.0.5 / 4.1.1+ Fix from $1,9502020-06-19 MEDIUM 6.1 CVE-2017-18879 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the author_link field of a Slack attachment. Mattermost Server 4.1.2 / 4.2.1+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2017-18880 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of a Slack attachment. Mattermost Server 4.1.2 / 4.2.1+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2017-18881 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command. Mattermost Server 4.1.2 / 4.2.1+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2017-18882 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data. Mattermost Server 4.1.2 / 4.2.1+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2017-18891 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link. Mattermost Server 4.0.5 / 4.1.1+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2017-18892 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutraliz… Mattermost Server 4.0.5 / 4.1.1+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2017-18893 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS. Mattermost Server 4.0.5 / 4.1.1+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18887 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members. Mattermost Server 4.1.2 / 4.2.1+ Fix from $1,6002020-06-19 MEDIUM 6.5 CVE-2017-18874 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve director… Mattermost Server 4.1.2 / 4.2.1+ Fix from $1,6002020-06-19 HIGH 8.8 CVE-2018-21264 An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response. Mattermost Server 4.5.2 / 4.6.2+ Fix from $1,9502020-06-19 MEDIUM 5.3 CVE-2017-18873 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) … Mattermost Server 4.1.2 / 4.2.1+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2019-20889 An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation. Mattermost Server 4.10.5 / 5.5.2+ Fix from $1,6002020-06-19 HIGH 8.8 CVE-2018-21263 An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a craft… Mattermost Server 4.5.2 / 4.6.2+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2018-21262 An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX tex… Mattermost Server 4.7.3+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2019-20880 An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consump… Mattermost Server 4.10.7 / 5.6.5+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2019-20885 An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file. Mattermost Server 5.8.0+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2019-20886 An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin. Mattermost Server 5.8.0+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2019-20888 An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumpti… Mattermost Server 4.10.5 / 5.5.2+ Fix from $1,9502020-06-19 HIGH 7.3 CVE-2019-20881 An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA. Mattermost Server 5.8.0+ Fix from $1,9502020-06-19 MEDIUM 5.4 CVE-2019-20876 An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy. Mattermost Server 4.10.8 / 5.7.3+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2018-21265 An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, au… Mattermost Desktop 4.0.0+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2019-20875 An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is… Mattermost Server 4.10.8 / 5.7.3+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2019-20877 An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whethe… Mattermost Server 4.10.8 / 5.7.3+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2019-20882 An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team. Mattermost Server 5.8.0+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2019-20884 An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post. Mattermost Server 5.8.0+ Fix from $1,6002020-06-19 CRITICAL 9.8 CVE-2018-21251 An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the param… Mattermost Server 5.1.1+ Fix from $2,3002020-06-19 HIGH 7.5 CVE-2018-21248 An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials. Mattermost Server 5.4.0+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2018-21258 An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command. Mattermost Server 5.1.0+ Fix from $1,9502020-06-19 MEDIUM 6.5 CVE-2018-21250 An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consump… Mattermost Server 4.10.4 / 5.1.2+ Fix from $1,6002020-06-19