Mattermost — безопасная платформа для совместной работы, позволяющая объединить ваши команды, инструменты и процессы для ускорения критически важной работы.
Релизный цикл, информация об уязвимостях
График релизов
Количество 264
CVE-2022-2406
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.
CVE-2022-2406
The legacy Slack import feature in Mattermost version 6.7.0 and earlie ...
GHSA-r4f6-w245-8wv4
Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.
GHSA-6vjc-mjgp-qm8w
An issue was discovered in Mattermost Mobile Apps before 1.31.2 on iOS. Unintended third-party servers could sometimes obtain authorization tokens, aka MMSA-2020-0022.
GHSA-hjj4-ch7m-p53m
An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device.
GHSA-wxj2-qc9p-65r3
Jenkins Mattermost Notification Plugin vulnerable to SSRF
GHSA-rgjp-xw8g-3xwx
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
GHSA-wmx6-cwpq-6j42
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.
CVE-2022-1003
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
CVE-2022-1003
One of the API in Mattermost version 6.3.0 and earlier fails to proper ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-2406 The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
CVE-2022-2406 The legacy Slack import feature in Mattermost version 6.7.0 and earlie ... | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-r4f6-w245-8wv4 Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost. | 57% Средний | больше 3 лет назад | ||
GHSA-6vjc-mjgp-qm8w An issue was discovered in Mattermost Mobile Apps before 1.31.2 on iOS. Unintended third-party servers could sometimes obtain authorization tokens, aka MMSA-2020-0022. | 0% Низкий | больше 3 лет назад | ||
GHSA-hjj4-ch7m-p53m An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device. | 1% Низкий | больше 3 лет назад | ||
GHSA-wxj2-qc9p-65r3 Jenkins Mattermost Notification Plugin vulnerable to SSRF | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-rgjp-xw8g-3xwx One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads. | CVSS3: 4.9 | 0% Низкий | почти 4 года назад | |
GHSA-wmx6-cwpq-6j42 Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations. | CVSS3: 5.4 | 0% Низкий | почти 4 года назад | |
CVE-2022-1003 One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads. | CVSS3: 3.3 | 0% Низкий | почти 4 года назад | |
CVE-2022-1003 One of the API in Mattermost version 6.3.0 and earlier fails to proper ... | CVSS3: 3.3 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу