CVE-2023-1774
- EPSS 0.15%
- Published 31.03.2023 12:15:06
- Last modified 21.11.2024 07:39:52
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.
CVE-2023-1775
- EPSS 0.18%
- Published 31.03.2023 12:15:06
- Last modified 21.11.2024 07:39:53
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Webs...
CVE-2023-1776
- EPSS 0.47%
- Published 31.03.2023 12:15:06
- Last modified 21.11.2024 07:39:53
Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.
CVE-2023-1777
- EPSS 0.18%
- Published 31.03.2023 12:15:06
- Last modified 21.11.2024 07:39:53
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
CVE-2023-1421
- EPSS 0.74%
- Published 15.03.2023 23:15:09
- Last modified 21.11.2024 07:39:09
A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.
CVE-2023-27266
- EPSS 0.17%
- Published 27.02.2023 15:15:12
- Last modified 21.11.2024 07:52:33
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
CVE-2023-27265
- EPSS 0.17%
- Published 27.02.2023 15:15:11
- Last modified 21.11.2024 07:52:33
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
CVE-2022-3257
- EPSS 0.56%
- Published 23.09.2022 15:15:13
- Last modified 21.11.2024 07:19:09
Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server...
CVE-2022-3147
- EPSS 0.85%
- Published 09.09.2022 15:15:15
- Last modified 21.11.2024 07:18:55
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denia...
CVE-2022-2401
- EPSS 0.33%
- Published 14.07.2022 18:15:08
- Last modified 21.11.2024 07:00:55
Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.