Mattermost

Mattermost Server

312 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Published 31.03.2023 12:15:06
  • Last modified 21.11.2024 07:39:52

When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.

  • EPSS 0.18%
  • Published 31.03.2023 12:15:06
  • Last modified 21.11.2024 07:39:53

When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Webs...

  • EPSS 0.47%
  • Published 31.03.2023 12:15:06
  • Last modified 21.11.2024 07:39:53

Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.

  • EPSS 0.18%
  • Published 31.03.2023 12:15:06
  • Last modified 21.11.2024 07:39:53

Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.

  • EPSS 0.74%
  • Published 15.03.2023 23:15:09
  • Last modified 21.11.2024 07:39:09

A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.

  • EPSS 0.17%
  • Published 27.02.2023 15:15:12
  • Last modified 21.11.2024 07:52:33

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

  • EPSS 0.17%
  • Published 27.02.2023 15:15:11
  • Last modified 21.11.2024 07:52:33

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

Exploit
  • EPSS 0.56%
  • Published 23.09.2022 15:15:13
  • Last modified 21.11.2024 07:19:09

Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server...

  • EPSS 0.85%
  • Published 09.09.2022 15:15:15
  • Last modified 21.11.2024 07:18:55

Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denia...

  • EPSS 0.33%
  • Published 14.07.2022 18:15:08
  • Last modified 21.11.2024 07:00:55

Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.