Логотип exploitDog
product: "mattermost"
Консоль
Логотип exploitDog

exploitDog

product: "mattermost"

Количество 232

Количество 232

debian логотип

CVE-2023-2786

около 2 лет назад

Mattermost fails to properly check thepermissions when executing comma ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-2785

около 2 лет назад

Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-2785

около 2 лет назад

Mattermost fails to properly truncate the postgres error log message o ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-2784

около 2 лет назад

Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install requests to the Apps.

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2023-2784

около 2 лет назад

Mattermost fails to verify if the requestor is a sysadmin or not, befo ...

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2023-2783

около 2 лет назад

Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-2783

около 2 лет назад

Mattermost Apps Framework fails to verify that a secret provided in th ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-27264

больше 2 лет назад

A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2023-27264

больше 2 лет назад

A missing permissions check in Mattermost Playbooks in Mattermost allo ...

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2023-27263

больше 2 лет назад

A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-27263

больше 2 лет назад

A missing permissions check in the /plugins/playbooks/api/v0/runs API ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-2514

около 2 лет назад

Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization. 

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2023-2514

около 2 лет назад

Mattermost Sever fails to redact the DB username and password before e ...

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2023-2193

около 2 лет назад

Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-2193

около 2 лет назад

Mattermost fails to invalidate existing authorization codes when deaut ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-1562

около 2 лет назад

Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2023-1562

около 2 лет назад

Mattermost fails to check the "Show Full Name" setting when rendering ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-4045

больше 2 лет назад

A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data. 

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2022-4045

больше 2 лет назад

A denial-of-service vulnerability in the Mattermost allows an authenti ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-4044

больше 2 лет назад

A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2023-2786

Mattermost fails to properly check thepermissions when executing comma ...

CVSS3: 4.3
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-2785

Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service

CVSS3: 4.3
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-2785

Mattermost fails to properly truncate the postgres error log message o ...

CVSS3: 4.3
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-2784

Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install requests to the Apps.

CVSS3: 4.2
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-2784

Mattermost fails to verify if the requestor is a sysadmin or not, befo ...

CVSS3: 4.2
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-2783

Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-2783

Mattermost Apps Framework fails to verify that a secret provided in th ...

CVSS3: 4.3
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-27264

A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-27264

A missing permissions check in Mattermost Playbooks in Mattermost allo ...

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-27263

A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-27263

A missing permissions check in the /plugins/playbooks/api/v0/runs API ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-2514

Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization. 

CVSS3: 6.7
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-2514

Mattermost Sever fails to redact the DB username and password before e ...

CVSS3: 6.7
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-2193

Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-2193

Mattermost fails to invalidate existing authorization codes when deaut ...

CVSS3: 6.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-1562

Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.

CVSS3: 3.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-1562

Mattermost fails to check the "Show Full Name" setting when rendering ...

CVSS3: 3.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2022-4045

A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data. 

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-4045

A denial-of-service vulnerability in the Mattermost allows an authenti ...

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-4044

A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу