Mattermost — безопасная платформа для совместной работы, позволяющая объединить ваши команды, инструменты и процессы для ускорения критически важной работы.
Релизный цикл, информация об уязвимостях
График релизов
Количество 232
CVE-2023-4106
Mattermost fails to check if the requesting user is a guest before per ...

CVE-2023-4105
Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message
CVE-2023-4105
Mattermost fails to delete the attachments when deleting a message in ...
GHSA-f56r-hfv8-q98c
Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection.

CVE-2023-3615
Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection.
GHSA-5j89-95rh-frfj
Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization.
GHSA-9v8g-3666-2499
Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg command.
GHSA-4qcm-px3r-jfr8
Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Service by sending a message containing a large number of escaped characters.
GHSA-7qj9-mfh7-vg26
Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an attacker to cause a denial-of-service by a linking to a specially crafted webpage in a message.
GHSA-w6f5-pv84-q7wv
Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink on a channel.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
CVE-2023-4106 Mattermost fails to check if the requesting user is a guest before per ... | CVSS3: 6.3 | 0% Низкий | почти 2 года назад | |
![]() | CVE-2023-4105 Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message | CVSS3: 3.1 | 0% Низкий | почти 2 года назад |
CVE-2023-4105 Mattermost fails to delete the attachments when deleting a message in ... | CVSS3: 3.1 | 0% Низкий | почти 2 года назад | |
GHSA-f56r-hfv8-q98c Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection. | CVSS3: 8.1 | 0% Низкий | почти 2 года назад | |
![]() | CVE-2023-3615 Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection. | CVSS3: 8.1 | 0% Низкий | почти 2 года назад |
GHSA-5j89-95rh-frfj Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization. | CVSS3: 6.7 | 0% Низкий | почти 2 года назад | |
GHSA-9v8g-3666-2499 Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg command. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
GHSA-4qcm-px3r-jfr8 Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Service by sending a message containing a large number of escaped characters. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
GHSA-7qj9-mfh7-vg26 Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an attacker to cause a denial-of-service by a linking to a specially crafted webpage in a message. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
GHSA-w6f5-pv84-q7wv Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink on a channel. | CVSS3: 3.1 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу