Vulnerability index

Browse CVEs

381 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2020-14449 An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to third-party servers, aka MMSA-202… Mattermost Mobile 1.30.0+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2020-14450 An issue was discovered in Mattermost Server before 5.22.0. The markdown renderer allows attackers to cause a denial of service (client-side), aka MM… Mattermost Server 5.22.0+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2020-14451 An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local Storage to remain after a logou… Mattermost Mobile 1.29.0+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2020-14453 An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, which allows attackers to cause … Mattermost Server 5.21.0+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2020-14458 An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel by name" API, aka MMSA-2020-… Mattermost Server 5.19.0+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2020-14459 An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a direct message, aka MMSA-2020… Mattermost Server 5.19.0+ Fix from $1,9502020-06-19 HIGH 7.3 CVE-2020-14456 An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, ak… Mattermost Desktop 4.4.0+ Fix from $1,9502020-06-19 MEDIUM 6.5 CVE-2020-14455 An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-20… Mattermost Desktop 4.4.0+ Fix from $1,6002020-06-19 MEDIUM 6.1 CVE-2020-14454 An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is… Mattermost Desktop 4.4.0+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2020-14452 An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014. Mattermost Server 5.21.0+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2020-14457 An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the update_team WebSocket event, aka… Mattermost Server 5.20.0+ Fix from $1,6002020-06-19 HIGH 8.8 CVE-2019-20841 An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for ac… Mattermost Server 5.9.7 / 5.15.4+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2019-20843 An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permissions for configuration files. Mattermost Server 5.9.7 / 5.15.4+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2019-20845 An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory consumption) via a large Slack i… Mattermost Server 5.18.0+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2019-20846 An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local file storage. Mattermost Server 5.18.0+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2019-20848 An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies. Mattermost Mobile 1.26.0+ Fix from $1,9502020-06-19 HIGH 7.2 CVE-2019-20842 An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by admins via SearchAllChannels. Mattermost Server 5.9.7 / 5.15.4+ Fix from $1,9502020-06-19 MEDIUM 6.5 CVE-2019-20844 An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a direct-message channel by chan… Mattermost Server 5.9.7 / 5.15.4+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2019-20847 An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any channel. Mattermost Server 5.18.0+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2019-20849 An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout. Mattermost Mobile 1.26.0+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2019-20850 An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout. Mattermost Mobile 1.26.0+ Fix from $1,6002020-06-19