CVE-2024-12247
- EPSS 0.17%
- Veröffentlicht 05.12.2024 16:15:25
- Zuletzt bearbeitet 01.10.2025 18:21:08
Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.
CVE-2024-11599
- EPSS 0.46%
- Veröffentlicht 28.11.2024 10:15:06
- Zuletzt bearbeitet 01.10.2025 18:25:03
Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registra...
CVE-2024-52032
- EPSS 0.3%
- Veröffentlicht 09.11.2024 18:15:15
- Zuletzt bearbeitet 14.11.2024 16:47:21
Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to get private channels names of channels that they are not a member of, w...
CVE-2024-36250
- EPSS 0.21%
- Veröffentlicht 09.11.2024 18:15:14
- Zuletzt bearbeitet 14.11.2024 17:11:23
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
CVE-2024-42000
- EPSS 0.29%
- Veröffentlicht 09.11.2024 18:15:14
- Zuletzt bearbeitet 14.11.2024 16:48:30
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels which allows a User or System Manager, with "Read Groups" permission but with no access for chann...
CVE-2024-46872
- EPSS 0.15%
- Veröffentlicht 29.10.2024 09:15:07
- Zuletzt bearbeitet 08.11.2024 15:00:42
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks
CVE-2024-47401
- EPSS 0.46%
- Veröffentlicht 29.10.2024 09:15:07
- Zuletzt bearbeitet 29.09.2025 14:47:01
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in...
CVE-2024-50052
- EPSS 0.28%
- Veröffentlicht 29.10.2024 08:15:12
- Zuletzt bearbeitet 29.09.2025 14:47:32
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.
CVE-2024-10241
- EPSS 0.3%
- Veröffentlicht 29.10.2024 08:15:11
- Zuletzt bearbeitet 30.09.2025 17:09:36
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
CVE-2024-9155
- EPSS 0.26%
- Veröffentlicht 26.09.2024 15:15:18
- Zuletzt bearbeitet 29.09.2025 13:50:51
Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have not been linked to a post which allows an attacker to view them in channels that they are a member of.