Количество 232
Количество 232
CVE-2023-2786
Mattermost fails to properly check thepermissions when executing comma ...

CVE-2023-2785
Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service
CVE-2023-2785
Mattermost fails to properly truncate the postgres error log message o ...

CVE-2023-2784
Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install requests to the Apps.
CVE-2023-2784
Mattermost fails to verify if the requestor is a sysadmin or not, befo ...

CVE-2023-2783
Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.
CVE-2023-2783
Mattermost Apps Framework fails to verify that a secret provided in th ...

CVE-2023-27264
A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.
CVE-2023-27264
A missing permissions check in Mattermost Playbooks in Mattermost allo ...

CVE-2023-27263
A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.
CVE-2023-27263
A missing permissions check in the /plugins/playbooks/api/v0/runs API ...

CVE-2023-2514
Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization.
CVE-2023-2514
Mattermost Sever fails to redact the DB username and password before e ...

CVE-2023-2193
Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token.
CVE-2023-2193
Mattermost fails to invalidate existing authorization codes when deaut ...

CVE-2023-1562
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
CVE-2023-1562
Mattermost fails to check the "Show Full Name" setting when rendering ...

CVE-2022-4045
A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data.
CVE-2022-4045
A denial-of-service vulnerability in the Mattermost allows an authenti ...

CVE-2022-4044
A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
CVE-2023-2786 Mattermost fails to properly check thepermissions when executing comma ... | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
![]() | CVE-2023-2785 Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service | CVSS3: 4.3 | 0% Низкий | около 2 лет назад |
CVE-2023-2785 Mattermost fails to properly truncate the postgres error log message o ... | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
![]() | CVE-2023-2784 Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install requests to the Apps. | CVSS3: 4.2 | 0% Низкий | около 2 лет назад |
CVE-2023-2784 Mattermost fails to verify if the requestor is a sysadmin or not, befo ... | CVSS3: 4.2 | 0% Низкий | около 2 лет назад | |
![]() | CVE-2023-2783 Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад |
CVE-2023-2783 Mattermost Apps Framework fails to verify that a secret provided in th ... | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
![]() | CVE-2023-27264 A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API. | CVSS3: 7.1 | 0% Низкий | больше 2 лет назад |
CVE-2023-27264 A missing permissions check in Mattermost Playbooks in Mattermost allo ... | CVSS3: 7.1 | 0% Низкий | больше 2 лет назад | |
![]() | CVE-2023-27263 A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад |
CVE-2023-27263 A missing permissions check in the /plugins/playbooks/api/v0/runs API ... | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
![]() | CVE-2023-2514 Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization. | CVSS3: 6.7 | 0% Низкий | около 2 лет назад |
CVE-2023-2514 Mattermost Sever fails to redact the DB username and password before e ... | CVSS3: 6.7 | 0% Низкий | около 2 лет назад | |
![]() | CVE-2023-2193 Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад |
CVE-2023-2193 Mattermost fails to invalidate existing authorization codes when deaut ... | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
![]() | CVE-2023-1562 Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner. | CVSS3: 3.5 | 0% Низкий | около 2 лет назад |
CVE-2023-1562 Mattermost fails to check the "Show Full Name" setting when rendering ... | CVSS3: 3.5 | 0% Низкий | около 2 лет назад | |
![]() | CVE-2022-4045 A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data. | CVSS3: 3.1 | 0% Низкий | больше 2 лет назад |
CVE-2022-4045 A denial-of-service vulnerability in the Mattermost allows an authenti ... | CVSS3: 3.1 | 0% Низкий | больше 2 лет назад | |
![]() | CVE-2022-4044 A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages. | CVSS3: 4.3 | 1% Низкий | больше 2 лет назад |
Уязвимостей на страницу