Mattermost — безопасная платформа для совместной работы, позволяющая объединить ваши команды, инструменты и процессы для ускорения критически важной работы.
Релизный цикл, информация об уязвимостях
График релизов
Количество 232

CVE-2024-39836
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails.
CVE-2024-39810
Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time l ...

CVE-2024-39810
Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path field, such as /dev/zero and, after testing the connection, cause the application to crash.
CVE-2024-32939
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...

CVE-2024-32939
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server."
GHSA-762m-4cx6-6mf4
Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling
GHSA-q22q-2rrf-m27p
Mattermost allows unsolicited invites to expose access to local channels
GHSA-56mc-f9w7-2wxq
Mattermost failed to disallow the modification of local users when syncing users in shared channels
GHSA-cmc8-222c-vqp9
Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel
GHSA-jq3g-xqpx-37x3
Mattermost failed to properly validate synced reactions
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2024-39836 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails. | CVSS3: 4.8 | 0% Низкий | 10 месяцев назад |
CVE-2024-39810 Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time l ... | CVSS3: 4.9 | 0% Низкий | 10 месяцев назад | |
![]() | CVE-2024-39810 Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path field, such as /dev/zero and, after testing the connection, cause the application to crash. | CVSS3: 4.9 | 0% Низкий | 10 месяцев назад |
CVE-2024-32939 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ... | CVSS3: 4.3 | 0% Низкий | 10 месяцев назад | |
![]() | CVE-2024-32939 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server." | CVSS3: 4.3 | 0% Низкий | 10 месяцев назад |
GHSA-762m-4cx6-6mf4 Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling | CVSS3: 6.8 | 0% Низкий | 11 месяцев назад | |
GHSA-q22q-2rrf-m27p Mattermost allows unsolicited invites to expose access to local channels | CVSS3: 8.7 | 0% Низкий | 11 месяцев назад | |
GHSA-56mc-f9w7-2wxq Mattermost failed to disallow the modification of local users when syncing users in shared channels | CVSS3: 7.4 | 0% Низкий | 11 месяцев назад | |
GHSA-cmc8-222c-vqp9 Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel | CVSS3: 8.7 | 0% Низкий | 11 месяцев назад | |
GHSA-jq3g-xqpx-37x3 Mattermost failed to properly validate synced reactions | CVSS3: 2.7 | 0% Низкий | 11 месяцев назад |
Уязвимостей на страницу