Количество 232
Количество 232
GHSA-m3fh-qqv6-hgxx
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.
GHSA-jqq9-5hrp-9jg8
Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.
GHSA-jq3g-xqpx-37x3
Mattermost failed to properly validate synced reactions
GHSA-jjr7-372r-cx7x
Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
GHSA-jj46-9cgh-qmfx
Mattermost Improper Access Control vulnerability
GHSA-jcgv-3pfq-j4hr
Mattermost Injection vulnerability
GHSA-j4c3-3h73-74m9
Mattermost Uncontrolled Resource Consumption vulnerability
GHSA-j3wj-gffr-9v8h
A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.
GHSA-hvvh-wh5g-3ppr
Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.
GHSA-hv5f-73mr-7vvj
Cross-site Scripting in Mattermost
GHSA-hrr7-x743-5wr4
Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.
GHSA-hrf9-rm95-fpf3
Mattermost Cross-Site Request Forgery vulnerability
GHSA-hqqj-g6mv-rw46
A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.
GHSA-hm57-h27x-599c
Mattermost incorrectly issues two sessions when using desktop SSO
GHSA-hjj4-ch7m-p53m
An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device.
GHSA-h8wh-f7gw-fwpr
Mattermost Incorrect Authorization vulnerability
GHSA-h69v-mvh9-hfrq
Mattermost Incorrect Authorization vulnerability
GHSA-g3v6-r8p9-wxg9
Mattermost fails to correctly delete attachments
GHSA-fv5r-cw7f-79jm
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.
GHSA-ffmx-32wf-j77f
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-m3fh-qqv6-hgxx Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older. | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
GHSA-jqq9-5hrp-9jg8 Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service. | 0% Низкий | больше 3 лет назад | ||
GHSA-jq3g-xqpx-37x3 Mattermost failed to properly validate synced reactions | CVSS3: 2.7 | 0% Низкий | 11 месяцев назад | |
GHSA-jjr7-372r-cx7x Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-jj46-9cgh-qmfx Mattermost Improper Access Control vulnerability | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-jcgv-3pfq-j4hr Mattermost Injection vulnerability | CVSS3: 3.1 | 0% Низкий | больше 1 года назад | |
GHSA-j4c3-3h73-74m9 Mattermost Uncontrolled Resource Consumption vulnerability | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-j3wj-gffr-9v8h A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-hvvh-wh5g-3ppr Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails. | 0% Низкий | больше 3 лет назад | ||
GHSA-hv5f-73mr-7vvj Cross-site Scripting in Mattermost | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-hrr7-x743-5wr4 Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
GHSA-hrf9-rm95-fpf3 Mattermost Cross-Site Request Forgery vulnerability | CVSS3: 4.6 | 0% Низкий | 10 месяцев назад | |
GHSA-hqqj-g6mv-rw46 A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-hm57-h27x-599c Mattermost incorrectly issues two sessions when using desktop SSO | CVSS3: 3.5 | 0% Низкий | 8 месяцев назад | |
GHSA-hjj4-ch7m-p53m An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device. | 1% Низкий | около 3 лет назад | ||
GHSA-h8wh-f7gw-fwpr Mattermost Incorrect Authorization vulnerability | CVSS3: 2.7 | 0% Низкий | больше 1 года назад | |
GHSA-h69v-mvh9-hfrq Mattermost Incorrect Authorization vulnerability | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-g3v6-r8p9-wxg9 Mattermost fails to correctly delete attachments | CVSS3: 3.1 | 0% Низкий | почти 2 года назад | |
GHSA-fv5r-cw7f-79jm The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API. | CVSS3: 6.5 | 0% Низкий | почти 3 года назад | |
GHSA-ffmx-32wf-j77f Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу