CVE-2022-1332
- EPSS 0.13%
- Veröffentlicht 13.04.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:30
One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file...
CVE-2022-1337
- EPSS 0.43%
- Veröffentlicht 13.04.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:31
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.
CVE-2022-0903
- EPSS 0.26%
- Veröffentlicht 10.03.2022 17:45:00
- Zuletzt bearbeitet 21.11.2024 06:39:38
A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.
CVE-2022-0904
- EPSS 0.45%
- Veröffentlicht 10.03.2022 17:45:00
- Zuletzt bearbeitet 21.11.2024 06:39:38
A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted Apple Pages document.
CVE-2021-37862
- EPSS 0.17%
- Veröffentlicht 17.12.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 06:15:59
Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.
CVE-2021-37863
- EPSS 0.57%
- Veröffentlicht 17.12.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 06:15:59
Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.
CVE-2016-11084
- EPSS 0.13%
- Veröffentlicht 19.06.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 02:45:27
An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
CVE-2017-18905
- EPSS 0.2%
- Veröffentlicht 19.06.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 03:21:13
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.
CVE-2017-18906
- EPSS 0.21%
- Veröffentlicht 19.06.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 03:21:13
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody else's account.
CVE-2017-18907
- EPSS 0.36%
- Veröffentlicht 19.06.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 03:21:13
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.