CVE-2018-21252
- EPSS 0.15%
- Published 19.06.2020 18:15:10
- Last modified 21.11.2024 04:03:17
An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail addresses to bypass a domain-based policy for signups.
CVE-2018-21256
- EPSS 0.15%
- Published 19.06.2020 18:15:10
- Last modified 21.11.2024 04:03:18
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for group-message channel creation) via the Group message slash command.
CVE-2018-21264
- EPSS 0.51%
- Published 19.06.2020 18:15:10
- Last modified 21.11.2024 04:03:19
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response.
CVE-2019-20889
- EPSS 0.15%
- Published 19.06.2020 17:15:14
- Last modified 21.11.2024 04:39:37
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation.
CVE-2019-20890
- EPSS 0.23%
- Published 19.06.2020 17:15:14
- Last modified 21.11.2024 04:39:37
An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions.
CVE-2018-21262
- EPSS 0.39%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:03:19
An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX text.
CVE-2018-21263
- EPSS 0.34%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:03:19
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response.
CVE-2019-20875
- EPSS 0.2%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:39:35
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.
CVE-2019-20876
- EPSS 0.35%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:39:35
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.
CVE-2019-20877
- EPSS 0.24%
- Published 19.06.2020 17:15:13
- Last modified 21.11.2024 04:39:35
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.