Логотип exploitDog
product: "mattermost"
Консоль
Логотип exploitDog

exploitDog

product: "mattermost"
Mattermost

Mattermostбезопасная платформа для совместной работы, позволяющая объединить ваши команды, инструменты и процессы для ускорения критически важной работы.

Релизный цикл, информация об уязвимостях

Продукт: Mattermost
Вендор: Mattermost

График релизов

5.46.16.26.37.06.47.17.27.38.07.42021202220232024202520262027202820292030

Недавние уязвимости Mattermost

Количество 263

nvd логотип

CVE-2024-39836

больше 1 года назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2024-39836

больше 1 года назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 a ...

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2024-39810

больше 1 года назад

Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path field, such as /dev/zero and, after testing the connection, cause the application to crash.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2024-39810

больше 1 года назад

Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time l ...

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2024-32939

больше 1 года назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server."

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-32939

больше 1 года назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-762m-4cx6-6mf4

больше 1 года назад

Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-q22q-2rrf-m27p

больше 1 года назад

Mattermost allows unsolicited invites to expose access to local channels

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-jq3g-xqpx-37x3

больше 1 года назад

Mattermost failed to properly validate synced reactions

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-56mc-f9w7-2wxq

больше 1 года назад

Mattermost failed to disallow the modification of local users when syncing users in shared channels

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-39836

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails.

CVSS3: 4.8
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-39836

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 a ...

CVSS3: 4.8
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-39810

Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path field, such as /dev/zero and, after testing the connection, cause the application to crash.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-39810

Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time l ...

CVSS3: 4.9
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-32939

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server."

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-32939

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-762m-4cx6-6mf4

Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-q22q-2rrf-m27p

Mattermost allows unsolicited invites to expose access to local channels

CVSS3: 8.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-jq3g-xqpx-37x3

Mattermost failed to properly validate synced reactions

CVSS3: 2.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-56mc-f9w7-2wxq

Mattermost failed to disallow the modification of local users when syncing users in shared channels

CVSS3: 7.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться