Mattermost — безопасная платформа для совместной работы, позволяющая объединить ваши команды, инструменты и процессы для ускорения критически важной работы.
Релизный цикл, информация об уязвимостях
График релизов
Количество 232
GHSA-r4f6-w245-8wv4
Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.
GHSA-6vjc-mjgp-qm8w
An issue was discovered in Mattermost Mobile Apps before 1.31.2 on iOS. Unintended third-party servers could sometimes obtain authorization tokens, aka MMSA-2020-0022.
GHSA-hjj4-ch7m-p53m
An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device.
GHSA-wxj2-qc9p-65r3
Jenkins Mattermost Notification Plugin vulnerable to SSRF
GHSA-rgjp-xw8g-3xwx
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
GHSA-wmx6-cwpq-6j42
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.

CVE-2022-1003
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
CVE-2022-1003
One of the API in Mattermost version 6.3.0 and earlier fails to proper ...

CVE-2022-1002
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.
CVE-2022-1002
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML conte ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
GHSA-r4f6-w245-8wv4 Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost. | 45% Средний | около 3 лет назад | ||
GHSA-6vjc-mjgp-qm8w An issue was discovered in Mattermost Mobile Apps before 1.31.2 on iOS. Unintended third-party servers could sometimes obtain authorization tokens, aka MMSA-2020-0022. | 0% Низкий | около 3 лет назад | ||
GHSA-hjj4-ch7m-p53m An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device. | 1% Низкий | около 3 лет назад | ||
GHSA-wxj2-qc9p-65r3 Jenkins Mattermost Notification Plugin vulnerable to SSRF | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-rgjp-xw8g-3xwx One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads. | CVSS3: 4.9 | 0% Низкий | больше 3 лет назад | |
GHSA-wmx6-cwpq-6j42 Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
![]() | CVE-2022-1003 One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads. | CVSS3: 3.3 | 0% Низкий | больше 3 лет назад |
CVE-2022-1003 One of the API in Mattermost version 6.3.0 and earlier fails to proper ... | CVSS3: 3.3 | 0% Низкий | больше 3 лет назад | |
![]() | CVE-2022-1002 Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations. | CVSS3: 2 | 0% Низкий | больше 3 лет назад |
CVE-2022-1002 Mattermost 6.3.0 and earlier fails to properly sanitize the HTML conte ... | CVSS3: 2 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу