CVE-2024-11599
- EPSS 0.33%
- Veröffentlicht 28.11.2024 10:15:06
- Zuletzt bearbeitet 01.10.2025 18:25:03
Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registra...
CVE-2024-52032
- EPSS 0.14%
- Veröffentlicht 09.11.2024 18:15:15
- Zuletzt bearbeitet 14.11.2024 16:47:21
Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to get private channels names of channels that they are not a member of, w...
CVE-2024-36250
- EPSS 0.07%
- Veröffentlicht 09.11.2024 18:15:14
- Zuletzt bearbeitet 14.11.2024 17:11:23
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
CVE-2024-42000
- EPSS 0.09%
- Veröffentlicht 09.11.2024 18:15:14
- Zuletzt bearbeitet 14.11.2024 16:48:30
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels which allows a User or System Manager, with "Read Groups" permission but with no access for chann...
CVE-2024-46872
- EPSS 0.08%
- Veröffentlicht 29.10.2024 09:15:07
- Zuletzt bearbeitet 08.11.2024 15:00:42
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks
CVE-2024-47401
- EPSS 0.26%
- Veröffentlicht 29.10.2024 09:15:07
- Zuletzt bearbeitet 29.09.2025 14:47:01
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in...
CVE-2024-50052
- EPSS 0.13%
- Veröffentlicht 29.10.2024 08:15:12
- Zuletzt bearbeitet 29.09.2025 14:47:32
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.
CVE-2024-10241
- EPSS 0.1%
- Veröffentlicht 29.10.2024 08:15:11
- Zuletzt bearbeitet 30.09.2025 17:09:36
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
CVE-2024-9155
- EPSS 0.1%
- Veröffentlicht 26.09.2024 15:15:18
- Zuletzt bearbeitet 29.09.2025 13:50:51
Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have not been linked to a post which allows an attacker to view them in channels that they are a member of.
CVE-2024-45843
- EPSS 0.07%
- Veröffentlicht 26.09.2024 08:15:06
- Zuletzt bearbeitet 26.09.2024 18:42:26
Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.