Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 300

Количество 300

github логотип

GHSA-m3fh-qqv6-hgxx

около 2 лет назад

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jqq9-5hrp-9jg8

больше 4 лет назад

Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

EPSS: Низкий
github логотип

GHSA-jq3g-xqpx-37x3

около 2 лет назад

Mattermost failed to properly validate synced reactions

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-jjr7-372r-cx7x

почти 3 года назад

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-jj46-9cgh-qmfx

почти 3 года назад

Mattermost Improper Access Control vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-jcgv-3pfq-j4hr

почти 3 года назад

Mattermost Injection vulnerability

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-j4c3-3h73-74m9

почти 3 года назад

Mattermost Uncontrolled Resource Consumption vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-j3wj-gffr-9v8h

больше 3 лет назад

A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hvvh-wh5g-3ppr

почти 5 лет назад

Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.

EPSS: Низкий
github логотип

GHSA-hv5f-73mr-7vvj

почти 5 лет назад

Cross-site Scripting in Mattermost

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-hrr7-x743-5wr4

около 3 лет назад

Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hrf9-rm95-fpf3

около 2 лет назад

Mattermost Cross-Site Request Forgery vulnerability

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-hqqj-g6mv-rw46

почти 4 года назад

A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hm57-h27x-599c

почти 2 года назад

Mattermost incorrectly issues two sessions when using desktop SSO

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-hjj4-ch7m-p53m

больше 4 лет назад

An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device.

EPSS: Низкий
github логотип

GHSA-h8wh-f7gw-fwpr

почти 3 года назад

Mattermost Incorrect Authorization vulnerability

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-h69v-mvh9-hfrq

почти 3 года назад

Mattermost Incorrect Authorization vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-g3v6-r8p9-wxg9

около 3 лет назад

Mattermost fails to correctly delete attachments

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-fv5r-cw7f-79jm

около 4 лет назад

The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-ffmx-32wf-j77f

больше 4 лет назад

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m3fh-qqv6-hgxx

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-jqq9-5hrp-9jg8

Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-jq3g-xqpx-37x3

Mattermost failed to properly validate synced reactions

CVSS3: 2.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-jjr7-372r-cx7x

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

CVSS3: 4.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-jj46-9cgh-qmfx

Mattermost Improper Access Control vulnerability

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-jcgv-3pfq-j4hr

Mattermost Injection vulnerability

CVSS3: 3.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-j4c3-3h73-74m9

Mattermost Uncontrolled Resource Consumption vulnerability

CVSS3: 4.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-j3wj-gffr-9v8h

A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-hvvh-wh5g-3ppr

Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.

1%
Низкий
почти 5 лет назад
github логотип
GHSA-hv5f-73mr-7vvj

Cross-site Scripting in Mattermost

CVSS3: 6.1
1%
Низкий
почти 5 лет назад
github логотип
GHSA-hrr7-x743-5wr4

Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-hrf9-rm95-fpf3

Mattermost Cross-Site Request Forgery vulnerability

CVSS3: 4.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-hqqj-g6mv-rw46

A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-hm57-h27x-599c

Mattermost incorrectly issues two sessions when using desktop SSO

CVSS3: 3.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-hjj4-ch7m-p53m

An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video Preview feature to overwrite arbitrary files on a device.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-h8wh-f7gw-fwpr

Mattermost Incorrect Authorization vulnerability

CVSS3: 2.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-h69v-mvh9-hfrq

Mattermost Incorrect Authorization vulnerability

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-g3v6-r8p9-wxg9

Mattermost fails to correctly delete attachments

CVSS3: 3.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-fv5r-cw7f-79jm

The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-ffmx-32wf-j77f

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу