Логотип exploitDog
product: "mattermost"
Консоль
Логотип exploitDog

exploitDog

product: "mattermost"
Mattermost

Mattermostбезопасная платформа для совместной работы, позволяющая объединить ваши команды, инструменты и процессы для ускорения критически важной работы.

Релизный цикл, информация об уязвимостях

Продукт: Mattermost
Вендор: Mattermost

График релизов

5.46.16.26.37.06.47.17.27.32021202220232024202520262027202820292030

Недавние уязвимости Mattermost

Количество 239

nvd логотип

CVE-2024-32939

12 месяцев назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server."

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-32939

12 месяцев назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-q22q-2rrf-m27p

около 1 года назад

Mattermost allows unsolicited invites to expose access to local channels

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-762m-4cx6-6mf4

около 1 года назад

Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-jq3g-xqpx-37x3

около 1 года назад

Mattermost failed to properly validate synced reactions

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-56mc-f9w7-2wxq

около 1 года назад

Mattermost failed to disallow the modification of local users when syncing users in shared channels

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-cmc8-222c-vqp9

около 1 года назад

Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2024-39832

около 1 года назад

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2024-39832

около 1 года назад

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9. ...

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2024-39777

около 1 года назад

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local channel, and that local channel will then become shared without the consent of the local admin.

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-32939

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server."

CVSS3: 4.3
0%
Низкий
12 месяцев назад
debian логотип
CVE-2024-32939

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...

CVSS3: 4.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-q22q-2rrf-m27p

Mattermost allows unsolicited invites to expose access to local channels

CVSS3: 8.7
0%
Низкий
около 1 года назад
github логотип
GHSA-762m-4cx6-6mf4

Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling

CVSS3: 6.8
0%
Низкий
около 1 года назад
github логотип
GHSA-jq3g-xqpx-37x3

Mattermost failed to properly validate synced reactions

CVSS3: 2.7
0%
Низкий
около 1 года назад
github логотип
GHSA-56mc-f9w7-2wxq

Mattermost failed to disallow the modification of local users when syncing users in shared channels

CVSS3: 7.4
0%
Низкий
около 1 года назад
github логотип
GHSA-cmc8-222c-vqp9

Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel

CVSS3: 8.7
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-39832

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled.

CVSS3: 6.8
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-39832

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9. ...

CVSS3: 6.8
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-39777

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local channel, and that local channel will then become shared without the consent of the local admin.

CVSS3: 8.7
0%
Низкий
около 1 года назад

Уязвимостей на страницу


Поделиться