Mattermost

Mattermost Server

312 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:09

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.

  • EPSS 0.36%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:09

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the author_link field of a Slack attachment.

  • EPSS 0.36%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:09

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of a Slack attachment.

  • EPSS 0.36%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:10

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command.

  • EPSS 0.36%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:10

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data.

  • EPSS 0.31%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:10

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.

  • EPSS 0.21%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:10

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.

  • EPSS 0.41%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:10

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.

  • EPSS 0.34%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:10

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.

  • EPSS 0.24%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:10

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.