Mattermost

Mattermost Server

388 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 09.01.2025 07:15:28
  • Zuletzt bearbeitet 02.10.2025 17:25:07

Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.

  • EPSS 0.08%
  • Veröffentlicht 09.01.2025 07:15:28
  • Zuletzt bearbeitet 29.09.2025 17:44:58

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.

  • EPSS 0.52%
  • Veröffentlicht 16.12.2024 08:15:05
  • Zuletzt bearbeitet 30.09.2025 15:49:33

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a...

  • EPSS 0.2%
  • Veröffentlicht 16.12.2024 08:15:05
  • Zuletzt bearbeitet 30.09.2025 15:50:38

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin.

  • EPSS 0.09%
  • Veröffentlicht 16.12.2024 08:15:04
  • Zuletzt bearbeitet 15.10.2025 14:13:31

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which allows an attacker to bypass of "Max failed attempts" restriction and se...

  • EPSS 0.08%
  • Veröffentlicht 05.12.2024 16:15:25
  • Zuletzt bearbeitet 01.10.2025 18:21:08

Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.

  • EPSS 0.07%
  • Veröffentlicht 28.11.2024 10:15:06
  • Zuletzt bearbeitet 01.10.2025 18:25:03

Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registra...

  • EPSS 0.42%
  • Veröffentlicht 09.11.2024 18:15:15
  • Zuletzt bearbeitet 14.11.2024 16:47:21

Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to get private channels names of channels that they are not a member of, w...

  • EPSS 0.29%
  • Veröffentlicht 09.11.2024 18:15:14
  • Zuletzt bearbeitet 14.11.2024 17:11:23

Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds

  • EPSS 0.19%
  • Veröffentlicht 09.11.2024 18:15:14
  • Zuletzt bearbeitet 14.11.2024 16:48:30

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels  which allows a User or System Manager, with "Read Groups" permission but with no access for chann...