Vulnerability index

Browse CVEs

381 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-48268 Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to cons… Mattermost after 9.0.1 Fix from $1,9502023-11-27 MEDIUM 6.1 CVE-2023-47168 Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" aft… Mattermost after 9.0.1 Fix from $1,6002023-11-27 MEDIUM 5.3 CVE-2023-48369 Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially o… Mattermost after 9.0.1 Fix from $1,6002023-11-27 HIGH 7.5 CVE-2023-40703 Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a attacker to consume excessiv… Mattermost after 9.0.1 Fix from $1,9502023-11-27 MEDIUM 5.4 CVE-2023-35075 Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML… Mattermost after 8.1.3 Fix from $1,6002023-11-27 MEDIUM 5.3 CVE-2023-5969 Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/r… Mattermost after 8.1.2 Fix from $1,6002023-11-06 MEDIUM 5.3 CVE-2023-5875 Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a … Mattermost Desktop 5.5.1+ Fix from $1,6002023-11-02 MEDIUM 5.3 CVE-2023-5876 Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial… Mattermost Desktop 5.5.1+ Fix from $1,6002023-11-02 MEDIUM 5.5 CVE-2023-5339 Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including pa… Mattermost Desktop after 5.4.0 Fix from $1,6002023-10-17 HIGH 7.5 CVE-2023-5330 Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to t… Mattermost Server 7.8.11 / 8.0.3+ Fix from $1,9502023-10-09 MEDIUM 6.5 CVE-2023-5333 Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sendin… Mattermost Server 7.8.11 / 8.0.3+ Fix from $1,6002023-10-09 MEDIUM 5.3 CVE-2023-5331 Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exposing unauthorized file infor… Mattermost Server 7.8.11 / 8.0.3+ Fix from $1,6002023-10-09 MEDIUM 6.5 CVE-2023-5196 Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_p… Mattermost 7.8.10 / 8.0.2+ Fix from $1,6002023-09-29 MEDIUM 5.4 CVE-2023-5195 Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not p… Mattermost 7.8.10 / 8.0.2+ Fix from $1,6002023-09-29 HIGH 8.2 CVE-2023-4478 Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thu… Mattermost Server 7.8.9 / 7.10.5+ Fix from $1,9502023-08-25 HIGH 7.5 CVE-2023-4108 Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged Mattermost 7.8.8 / 7.9.6+ Fix from $1,9502023-08-11 MEDIUM 6.5 CVE-2023-4106 Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to … Mattermost 7.8.8 / 7.9.6+ Fix from $1,6002023-08-11 MEDIUM 6.5 CVE-2023-4107 Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin'… Mattermost 7.8.8 / 7.9.6+ Fix from $1,6002023-08-11 HIGH 8.1 CVE-2023-3615 Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept t… Mattermost 2.5.1+ Fix from $1,9502023-07-17 MEDIUM 6.5 CVE-2023-3593 Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input. Mattermost Server 7.8.7 / 7.9.5+ Fix from $1,6002023-07-17 HIGH 8.2 CVE-2023-3591 Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created. Mattermost Server 7.8.7 / 7.9.5+ Fix from $1,9502023-07-17 HIGH 8.1 CVE-2023-3581 Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs. Mattermost Server 7.8.7 / 7.9.5+ Fix from $1,9502023-07-17 HIGH 7.5 CVE-2023-3590 Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments. Mattermost Server 7.10.3+ Fix from $1,9502023-07-17 MEDIUM 5.4 CVE-2023-3586 Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared … Mattermost Server 7.8.7 / 7.9.5+ Fix from $1,6002023-07-17 MEDIUM 6.5 CVE-2023-2792 Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg com… Mattermost after 7.9.3 Fix from $1,6002023-06-16 MEDIUM 6.5 CVE-2023-2793 Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an attacker to cause a denial-of-s… Mattermost after 7.9.2 Fix from $1,6002023-06-16 MEDIUM 6.5 CVE-2023-2797 Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink… Mattermost after 7.8.4 Fix from $1,6002023-06-16 MEDIUM 6.5 CVE-2023-2831 Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Service by sending a message conta… Mattermost after 7.9.3 Fix from $1,6002023-06-16 MEDIUM 6.5 CVE-2023-2784 Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install… Mattermost after 7.9.3 Fix from $1,6002023-06-16 MEDIUM 6.5 CVE-2023-2787 Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message thre… Mattermost after 7.9.3 Fix from $1,6002023-06-16