Mattermost — безопасная платформа для совместной работы, позволяющая объединить ваши команды, инструменты и процессы для ускорения критически важной работы.
Релизный цикл, информация об уязвимостях
График релизов
Количество 300
CVE-2023-2831
Mattermost fails to unescape Markdown strings in a memory-efficient wa ...
CVE-2023-2797
Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink on a channel.
CVE-2023-2797
Mattermost fails to sanitize code permalinks, allowing an attacker to ...
CVE-2023-2793
Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an attacker to cause a denial-of-service by a linking to a specially crafted webpage in a message.
CVE-2023-2793
Mattermost fails to validate links on external websites when construct ...
CVE-2023-2792
Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg command.
CVE-2023-2792
Mattermost fails to sanitize ephemeral error messages, allowing an att ...
CVE-2023-2785
Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service
CVE-2023-2785
Mattermost fails to properly truncate the postgres error log message o ...
GHSA-8jf2-78m7-7f8v
Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install requests to the Apps.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2023-2831 Mattermost fails to unescape Markdown strings in a memory-efficient wa ... | CVSS3: 4.3 | 1% Низкий | около 3 лет назад | |
CVE-2023-2797 Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink on a channel. | CVSS3: 3.1 | 0% Низкий | около 3 лет назад | |
CVE-2023-2797 Mattermost fails to sanitize code permalinks, allowing an attacker to ... | CVSS3: 3.1 | 0% Низкий | около 3 лет назад | |
CVE-2023-2793 Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an attacker to cause a denial-of-service by a linking to a specially crafted webpage in a message. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-2793 Mattermost fails to validate links on external websites when construct ... | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-2792 Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg command. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-2792 Mattermost fails to sanitize ephemeral error messages, allowing an att ... | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-2785 Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service | CVSS3: 4.3 | 1% Низкий | около 3 лет назад | |
CVE-2023-2785 Mattermost fails to properly truncate the postgres error log message o ... | CVSS3: 4.3 | 1% Низкий | около 3 лет назад | |
GHSA-8jf2-78m7-7f8v Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install requests to the Apps. | CVSS3: 4.2 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу