Mattermost — безопасная платформа для совместной работы, позволяющая объединить ваши команды, инструменты и процессы для ускорения критически важной работы.
Релизный цикл, информация об уязвимостях
График релизов
Количество 300
GHSA-hjj4-ch7m-p53m
An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device.
GHSA-wxj2-qc9p-65r3
Jenkins Mattermost Notification Plugin vulnerable to SSRF
GHSA-rgjp-xw8g-3xwx
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
GHSA-wmx6-cwpq-6j42
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.
CVE-2022-1003
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
CVE-2022-1003
One of the API in Mattermost version 6.3.0 and earlier fails to proper ...
CVE-2022-1002
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.
CVE-2022-1002
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML conte ...
GHSA-ffmx-32wf-j77f
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.
CVE-2022-0708
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-hjj4-ch7m-p53m An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device. | 1% Низкий | около 4 лет назад | ||
GHSA-wxj2-qc9p-65r3 Jenkins Mattermost Notification Plugin vulnerable to SSRF | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-rgjp-xw8g-3xwx One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads. | CVSS3: 4.9 | 0% Низкий | больше 4 лет назад | |
GHSA-wmx6-cwpq-6j42 Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1003 One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads. | CVSS3: 3.3 | 0% Низкий | больше 4 лет назад | |
CVE-2022-1003 One of the API in Mattermost version 6.3.0 and earlier fails to proper ... | CVSS3: 3.3 | 0% Низкий | больше 4 лет назад | |
CVE-2022-1002 Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations. | CVSS3: 2 | 1% Низкий | больше 4 лет назад | |
CVE-2022-1002 Mattermost 6.3.0 and earlier fails to properly sanitize the HTML conte ... | CVSS3: 2 | 1% Низкий | больше 4 лет назад | |
GHSA-ffmx-32wf-j77f Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure. | 1% Низкий | больше 4 лет назад | ||
CVE-2022-0708 Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure. | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу