Логотип exploitDog
product: "mattermost"
Консоль
Логотип exploitDog

exploitDog

product: "mattermost"

Количество 232

Количество 232

github логотип

GHSA-m3fh-qqv6-hgxx

10 месяцев назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jqq9-5hrp-9jg8

больше 3 лет назад

Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

EPSS: Низкий
github логотип

GHSA-jq3g-xqpx-37x3

11 месяцев назад

Mattermost failed to properly validate synced reactions

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-jjr7-372r-cx7x

больше 1 года назад

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-jj46-9cgh-qmfx

больше 1 года назад

Mattermost Improper Access Control vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-jcgv-3pfq-j4hr

больше 1 года назад

Mattermost Injection vulnerability

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-j4c3-3h73-74m9

больше 1 года назад

Mattermost Uncontrolled Resource Consumption vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-j3wj-gffr-9v8h

больше 2 лет назад

A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hvvh-wh5g-3ppr

больше 3 лет назад

Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.

EPSS: Низкий
github логотип

GHSA-hv5f-73mr-7vvj

больше 3 лет назад

Cross-site Scripting in Mattermost

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-hrr7-x743-5wr4

около 2 лет назад

Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hrf9-rm95-fpf3

10 месяцев назад

Mattermost Cross-Site Request Forgery vulnerability

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-hqqj-g6mv-rw46

больше 2 лет назад

A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hm57-h27x-599c

8 месяцев назад

Mattermost incorrectly issues two sessions when using desktop SSO

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-hjj4-ch7m-p53m

около 3 лет назад

An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device.

EPSS: Низкий
github логотип

GHSA-h8wh-f7gw-fwpr

больше 1 года назад

Mattermost Incorrect Authorization vulnerability

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-h69v-mvh9-hfrq

больше 1 года назад

Mattermost Incorrect Authorization vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-g3v6-r8p9-wxg9

почти 2 года назад

Mattermost fails to correctly delete attachments

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-fv5r-cw7f-79jm

почти 3 года назад

The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-ffmx-32wf-j77f

больше 3 лет назад

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m3fh-qqv6-hgxx

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-jqq9-5hrp-9jg8

Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-jq3g-xqpx-37x3

Mattermost failed to properly validate synced reactions

CVSS3: 2.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-jjr7-372r-cx7x

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-jj46-9cgh-qmfx

Mattermost Improper Access Control vulnerability

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-jcgv-3pfq-j4hr

Mattermost Injection vulnerability

CVSS3: 3.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-j4c3-3h73-74m9

Mattermost Uncontrolled Resource Consumption vulnerability

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-j3wj-gffr-9v8h

A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-hvvh-wh5g-3ppr

Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hv5f-73mr-7vvj

Cross-site Scripting in Mattermost

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-hrr7-x743-5wr4

Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-hrf9-rm95-fpf3

Mattermost Cross-Site Request Forgery vulnerability

CVSS3: 4.6
0%
Низкий
10 месяцев назад
github логотип
GHSA-hqqj-g6mv-rw46

A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-hm57-h27x-599c

Mattermost incorrectly issues two sessions when using desktop SSO

CVSS3: 3.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-hjj4-ch7m-p53m

An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device.

1%
Низкий
около 3 лет назад
github логотип
GHSA-h8wh-f7gw-fwpr

Mattermost Incorrect Authorization vulnerability

CVSS3: 2.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-h69v-mvh9-hfrq

Mattermost Incorrect Authorization vulnerability

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-g3v6-r8p9-wxg9

Mattermost fails to correctly delete attachments

CVSS3: 3.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-fv5r-cw7f-79jm

The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-ffmx-32wf-j77f

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу