Vulnerability index

Browse CVEs

381 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2023-2788 Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persi… Mattermost after 7.9.3 Fix from $1,6002023-06-16 MEDIUM 5.3 CVE-2023-2808 Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to tr… Mattermost 7.1.9 / 7.8.4+ Fix from $1,6002023-05-29 HIGH 8.8 CVE-2023-2515 Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to syst… Mattermost Server 7.1.8 / 7.7.4+ Fix from $1,9502023-05-12 HIGH 7.5 CVE-2023-2514 Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization.  Mattermost after 7.9.1 Fix from $1,9502023-05-12 MEDIUM 5.4 CVE-2023-2000 Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website Mattermost Desktop after 5.2.2 Fix from $1,6002023-05-02 CRITICAL 9.1 CVE-2023-2193 Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code t… Mattermost Mitigation only Fix from $2,3002023-04-20 HIGH 7.5 CVE-2023-1831 Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental … Mattermost Server 7.7.3 / 7.8.2+ Fix from $1,9502023-04-17 MEDIUM 6.5 CVE-2023-1775 When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all use… Mattermost Server 7.1.6+ Fix from $1,6002023-03-31 MEDIUM 5.4 CVE-2023-1774 When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an at… Mattermost Server 7.1.6+ Fix from $1,6002023-03-31 MEDIUM 5.4 CVE-2023-1776 Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file. Mattermost Server 7.1.6+ Fix from $1,6002023-03-31 MEDIUM 5.3 CVE-2023-1777 Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the con… Mattermost Server 7.1.6+ Fix from $1,6002023-03-31 MEDIUM 6.1 CVE-2023-1421 A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behal… Mattermost Server 7.7.0+ Fix from $1,6002023-03-15 MEDIUM 6.5 CVE-2023-27263 A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team… Mattermost after 7.1.4 Fix from $1,6002023-02-27 MEDIUM 6.5 CVE-2023-27264 A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks… Mattermost after 7.1.4 Fix from $1,6002023-02-27 MEDIUM 6.5 CVE-2022-4045 A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoint… Mattermost Mitigation only Fix from $1,6002022-11-23 MEDIUM 6.5 CVE-2022-4019 A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to … Mattermost Mitigation only Fix from $1,6002022-11-23 MEDIUM 6.5 CVE-2022-4044 A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages. Mattermost 7.4+ Fix from $1,6002022-11-23 MEDIUM 6.5 CVE-2022-3257 Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which a… Mattermost Server 7.2.0+ Fix from $1,6002022-09-23 MEDIUM 6.5 CVE-2022-3147 Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated… Mattermost Server 7.1.0+ Fix from $1,6002022-09-09 MEDIUM 6.5 CVE-2022-2401 Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by … Mattermost Server 6.3.9 / 6.5.2+ Fix from $1,6002022-07-14 MEDIUM 6.5 CVE-2022-2406 The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenti… Mattermost after 6.5.1 Fix from $1,6002022-07-14 MEDIUM 5.3 CVE-2022-2366 Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations … Mattermost Server 6.3.9 / 6.5.2+ Fix from $1,6002022-07-12 MEDIUM 6.5 CVE-2022-1982 Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG atta… Mattermost Server 6.3.8 / 6.4.3+ Fix from $1,6002022-06-02 HIGH 8.8 CVE-2022-1548 Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membe… Playbooks after 1.25.0 Fix from $1,9502022-05-03 HIGH 8.8 CVE-2022-1384 Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an auth… Mattermost Server 6.5.0+ Fix from $1,9502022-04-19 MEDIUM 6.5 CVE-2022-1333 Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorize… Playbooks after 1.24.0 Fix from $1,6002022-04-13 MEDIUM 6.5 CVE-2022-1337 The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authentica… Mattermost Server 5.37.9 / 6.2.5+ Fix from $1,6002022-04-13 MEDIUM 5.4 CVE-2022-1002 Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users w… Mattermost 6.4.0+ Fix from $1,6002022-03-18 HIGH 7.5 CVE-2022-0903 A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server… Mattermost Server 5.37.8 / 6.1.3+ Fix from $1,9502022-03-10 MEDIUM 6.5 CVE-2022-0904 A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via … Mattermost Server 5.37.8 / 6.1.3+ Fix from $1,6002022-03-10