Логотип exploitDog
product: "mattermost"
Консоль
Логотип exploitDog

exploitDog

product: "mattermost"
Mattermost

Mattermostбезопасная платформа для совместной работы, позволяющая объединить ваши команды, инструменты и процессы для ускорения критически важной работы.

Релизный цикл, информация об уязвимостях

Продукт: Mattermost
Вендор: Mattermost

График релизов

5.46.16.26.37.06.47.17.27.32021202220232024202520262027202820292030

Недавние уязвимости Mattermost

Количество 239

nvd логотип

CVE-2024-43813

12 месяцев назад

Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any user.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-43813

12 месяцев назад

Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce p ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-42411

12 месяцев назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-42411

12 месяцев назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-40886

12 месяцев назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in User Management page of the system console.

CVSS3: 4.6
EPSS: Низкий
debian логотип

CVE-2024-40886

12 месяцев назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2024-39836

12 месяцев назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2024-39836

12 месяцев назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 a ...

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2024-39810

12 месяцев назад

Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path field, such as /dev/zero and, after testing the connection, cause the application to crash.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2024-39810

12 месяцев назад

Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time l ...

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-43813

Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any user.

CVSS3: 4.3
0%
Низкий
12 месяцев назад
debian логотип
CVE-2024-43813

Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce p ...

CVSS3: 4.3
0%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-42411

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.

CVSS3: 5.3
0%
Низкий
12 месяцев назад
debian логотип
CVE-2024-42411

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...

CVSS3: 5.3
0%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-40886

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in User Management page of the system console.

CVSS3: 4.6
0%
Низкий
12 месяцев назад
debian логотип
CVE-2024-40886

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...

CVSS3: 4.6
0%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-39836

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails.

CVSS3: 4.8
0%
Низкий
12 месяцев назад
debian логотип
CVE-2024-39836

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 a ...

CVSS3: 4.8
0%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-39810

Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path field, such as /dev/zero and, after testing the connection, cause the application to crash.

CVSS3: 4.9
0%
Низкий
12 месяцев назад
debian логотип
CVE-2024-39810

Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time l ...

CVSS3: 4.9
0%
Низкий
12 месяцев назад

Уязвимостей на страницу


Поделиться