Mattermost

Mattermost Server

312 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Published 21.03.2025 08:24:13
  • Last modified 27.03.2025 15:01:59

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels.

  • EPSS 0.05%
  • Published 21.03.2025 08:23:20
  • Last modified 27.03.2025 14:55:25

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public

  • EPSS 0.04%
  • Published 21.03.2025 08:22:25
  • Last modified 27.03.2025 15:01:03

Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining private channels via crafted permalink links without explicit consent from them.

  • EPSS 0.05%
  • Published 19.03.2025 14:11:03
  • Last modified 01.10.2025 18:05:48

Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.

  • EPSS 0.14%
  • Published 24.02.2025 08:15:10
  • Last modified 18.08.2025 18:22:38

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicating a board, which allows a user to read any arbitrary file on the system via duplicating a specially...

  • EPSS 0.11%
  • Published 24.02.2025 08:15:10
  • Last modified 01.10.2025 18:03:04

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards reordering which allows an attacker to retrieve data from the database, via a SQL injection when reo...

  • EPSS 0.06%
  • Published 24.02.2025 08:15:10
  • Last modified 01.10.2025 18:03:20

Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when the "Allow users to view archived channels" is disabled which allows a user to expo...

  • EPSS 22.02%
  • Published 24.02.2025 08:15:10
  • Last modified 02.10.2025 18:19:20

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a...

  • EPSS 0.05%
  • Published 24.02.2025 08:15:09
  • Last modified 01.10.2025 18:02:32

Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.

  • EPSS 0.05%
  • Published 14.02.2025 18:15:23
  • Last modified 29.09.2025 18:11:58

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.