Mattermost

Mattermost Server

388 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 15.04.2026 11:00:14
  • Zuletzt bearbeitet 22.04.2026 19:41:52

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish multiple i...

  • EPSS 0.02%
  • Veröffentlicht 15.04.2026 10:13:33
  • Zuletzt bearbeitet 22.04.2026 19:42:25

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpoint which allows an attacker to update a user's authentication method via a CSRF attack by tricking a...

  • EPSS 0.03%
  • Veröffentlicht 15.04.2026 10:11:07
  • Zuletzt bearbeitet 22.04.2026 19:43:52

Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of ...

  • EPSS 0.05%
  • Veröffentlicht 09.04.2026 10:09:23
  • Zuletzt bearbeitet 25.04.2026 18:02:06

Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost A...

  • EPSS 0.02%
  • Veröffentlicht 26.03.2026 16:29:54
  • Zuletzt bearbeitet 30.03.2026 19:42:39

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate Advanced Logging file target paths which allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON config...

  • EPSS 0.03%
  • Veröffentlicht 26.03.2026 16:23:05
  • Zuletzt bearbeitet 30.03.2026 19:40:01

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restrictions when retrieving group member IDs, which allows authenticated guest users to enumerate user IDs outside their allowed visibil...

  • EPSS 0.04%
  • Veröffentlicht 26.03.2026 16:21:19
  • Zuletzt bearbeitet 30.03.2026 19:40:45

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompressed archive entry sizes during file extraction which allows authenticated users with file upload permissions to cause a denial of ...

  • EPSS 0.01%
  • Veröffentlicht 26.03.2026 16:18:06
  • Zuletzt bearbeitet 30.03.2026 19:41:30

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on downloaded bulk export which allows other local users on the server to be able to read contents of the bulk export.. Mattermost A...

  • EPSS 0.02%
  • Veröffentlicht 26.03.2026 16:16:49
  • Zuletzt bearbeitet 30.03.2026 19:45:27

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mmctl commands terminal output which allows attackers to manipulate administrator terminals via crafted...

  • EPSS 0.03%
  • Veröffentlicht 26.03.2026 10:43:24
  • Zuletzt bearbeitet 26.03.2026 18:48:39

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing membership sync from a remote cluster, which allows a malicious remote cluster to grant a user access to ...