Mattermost — безопасная платформа для совместной работы, позволяющая объединить ваши команды, инструменты и процессы для ускорения критически важной работы.
Релизный цикл, информация об уязвимостях
График релизов
Количество 263
CVE-2024-39836
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails.
CVE-2024-39836
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 a ...
CVE-2024-39810
Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path field, such as /dev/zero and, after testing the connection, cause the application to crash.
CVE-2024-39810
Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time l ...
CVE-2024-32939
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server."
CVE-2024-32939
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...
GHSA-762m-4cx6-6mf4
Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling
GHSA-q22q-2rrf-m27p
Mattermost allows unsolicited invites to expose access to local channels
GHSA-jq3g-xqpx-37x3
Mattermost failed to properly validate synced reactions
GHSA-56mc-f9w7-2wxq
Mattermost failed to disallow the modification of local users when syncing users in shared channels
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-39836 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails. | CVSS3: 4.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-39836 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 a ... | CVSS3: 4.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-39810 Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path field, such as /dev/zero and, after testing the connection, cause the application to crash. | CVSS3: 4.9 | 0% Низкий | больше 1 года назад | |
CVE-2024-39810 Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time l ... | CVSS3: 4.9 | 0% Низкий | больше 1 года назад | |
CVE-2024-32939 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server." | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2024-32939 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ... | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-762m-4cx6-6mf4 Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling | CVSS3: 6.8 | 0% Низкий | больше 1 года назад | |
GHSA-q22q-2rrf-m27p Mattermost allows unsolicited invites to expose access to local channels | CVSS3: 8.7 | 0% Низкий | больше 1 года назад | |
GHSA-jq3g-xqpx-37x3 Mattermost failed to properly validate synced reactions | CVSS3: 2.7 | 0% Низкий | больше 1 года назад | |
GHSA-56mc-f9w7-2wxq Mattermost failed to disallow the modification of local users when syncing users in shared channels | CVSS3: 7.4 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу