Логотип exploitDog
product: "mattermost"
Консоль
Логотип exploitDog

exploitDog

product: "mattermost"

Количество 249

Количество 249

github логотип

GHSA-m3fh-qqv6-hgxx

больше 1 года назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jqq9-5hrp-9jg8

почти 4 года назад

Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

EPSS: Низкий
github логотип

GHSA-jq3g-xqpx-37x3

больше 1 года назад

Mattermost failed to properly validate synced reactions

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-jjr7-372r-cx7x

около 2 лет назад

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-jj46-9cgh-qmfx

около 2 лет назад

Mattermost Improper Access Control vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-jcgv-3pfq-j4hr

около 2 лет назад

Mattermost Injection vulnerability

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-j4c3-3h73-74m9

около 2 лет назад

Mattermost Uncontrolled Resource Consumption vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-j3wj-gffr-9v8h

почти 3 года назад

A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hvvh-wh5g-3ppr

около 4 лет назад

Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.

EPSS: Низкий
github логотип

GHSA-hv5f-73mr-7vvj

около 4 лет назад

Cross-site Scripting in Mattermost

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-hrr7-x743-5wr4

больше 2 лет назад

Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hrf9-rm95-fpf3

больше 1 года назад

Mattermost Cross-Site Request Forgery vulnerability

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-hqqj-g6mv-rw46

около 3 лет назад

A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hm57-h27x-599c

около 1 года назад

Mattermost incorrectly issues two sessions when using desktop SSO

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-hjj4-ch7m-p53m

больше 3 лет назад

An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device.

EPSS: Низкий
github логотип

GHSA-h8wh-f7gw-fwpr

около 2 лет назад

Mattermost Incorrect Authorization vulnerability

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-h69v-mvh9-hfrq

около 2 лет назад

Mattermost Incorrect Authorization vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-g3v6-r8p9-wxg9

больше 2 лет назад

Mattermost fails to correctly delete attachments

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-fv5r-cw7f-79jm

больше 3 лет назад

The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-ffmx-32wf-j77f

почти 4 года назад

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m3fh-qqv6-hgxx

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-jqq9-5hrp-9jg8

Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

1%
Низкий
почти 4 года назад
github логотип
GHSA-jq3g-xqpx-37x3

Mattermost failed to properly validate synced reactions

CVSS3: 2.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-jjr7-372r-cx7x

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-jj46-9cgh-qmfx

Mattermost Improper Access Control vulnerability

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-jcgv-3pfq-j4hr

Mattermost Injection vulnerability

CVSS3: 3.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-j4c3-3h73-74m9

Mattermost Uncontrolled Resource Consumption vulnerability

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-j3wj-gffr-9v8h

A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-hvvh-wh5g-3ppr

Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.

0%
Низкий
около 4 лет назад
github логотип
GHSA-hv5f-73mr-7vvj

Cross-site Scripting in Mattermost

CVSS3: 6.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-hrr7-x743-5wr4

Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-hrf9-rm95-fpf3

Mattermost Cross-Site Request Forgery vulnerability

CVSS3: 4.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-hqqj-g6mv-rw46

A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-hm57-h27x-599c

Mattermost incorrectly issues two sessions when using desktop SSO

CVSS3: 3.5
0%
Низкий
около 1 года назад
github логотип
GHSA-hjj4-ch7m-p53m

An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-h8wh-f7gw-fwpr

Mattermost Incorrect Authorization vulnerability

CVSS3: 2.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-h69v-mvh9-hfrq

Mattermost Incorrect Authorization vulnerability

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-g3v6-r8p9-wxg9

Mattermost fails to correctly delete attachments

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-fv5r-cw7f-79jm

The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-ffmx-32wf-j77f

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу