Mattermost — безопасная платформа для совместной работы, позволяющая объединить ваши команды, инструменты и процессы для ускорения критически важной работы.
Релизный цикл, информация об уязвимостях
График релизов
Количество 239

CVE-2024-32939
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server."
CVE-2024-32939
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...
GHSA-q22q-2rrf-m27p
Mattermost allows unsolicited invites to expose access to local channels
GHSA-762m-4cx6-6mf4
Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling
GHSA-jq3g-xqpx-37x3
Mattermost failed to properly validate synced reactions
GHSA-56mc-f9w7-2wxq
Mattermost failed to disallow the modification of local users when syncing users in shared channels
GHSA-cmc8-222c-vqp9
Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel

CVE-2024-39832
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled.
CVE-2024-39832
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9. ...

CVE-2024-39777
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local channel, and that local channel will then become shared without the consent of the local admin.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2024-32939 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server." | CVSS3: 4.3 | 0% Низкий | 12 месяцев назад |
CVE-2024-32939 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ... | CVSS3: 4.3 | 0% Низкий | 12 месяцев назад | |
GHSA-q22q-2rrf-m27p Mattermost allows unsolicited invites to expose access to local channels | CVSS3: 8.7 | 0% Низкий | около 1 года назад | |
GHSA-762m-4cx6-6mf4 Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling | CVSS3: 6.8 | 0% Низкий | около 1 года назад | |
GHSA-jq3g-xqpx-37x3 Mattermost failed to properly validate synced reactions | CVSS3: 2.7 | 0% Низкий | около 1 года назад | |
GHSA-56mc-f9w7-2wxq Mattermost failed to disallow the modification of local users when syncing users in shared channels | CVSS3: 7.4 | 0% Низкий | около 1 года назад | |
GHSA-cmc8-222c-vqp9 Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel | CVSS3: 8.7 | 0% Низкий | около 1 года назад | |
![]() | CVE-2024-39832 Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled. | CVSS3: 6.8 | 0% Низкий | около 1 года назад |
CVE-2024-39832 Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9. ... | CVSS3: 6.8 | 0% Низкий | около 1 года назад | |
![]() | CVE-2024-39777 Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local channel, and that local channel will then become shared without the consent of the local admin. | CVSS3: 8.7 | 0% Низкий | около 1 года назад |
Уязвимостей на страницу