CVE-2019-20888
- EPSS 0.39%
- Veröffentlicht 19.06.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:39:37
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumption) via an outgoing webhook or a slash command integration.
CVE-2017-18875
- EPSS 0.18%
- Veröffentlicht 19.06.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 03:21:09
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can create arbitrary files.
CVE-2017-18876
- EPSS 0.26%
- Veröffentlicht 19.06.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 03:21:09
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.
CVE-2017-18877
- EPSS 0.36%
- Veröffentlicht 19.06.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 03:21:09
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page.
CVE-2018-21248
- EPSS 0.25%
- Veröffentlicht 19.06.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:03:17
An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials.
CVE-2018-21249
- EPSS 0.24%
- Veröffentlicht 19.06.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:03:17
An issue was discovered in Mattermost Server before 5.3.0. It mishandles timing.
CVE-2018-21250
- EPSS 0.39%
- Veröffentlicht 19.06.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:03:17
An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consumption) via crafted image dimensions.
CVE-2018-21251
- EPSS 0.41%
- Veröffentlicht 19.06.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:03:17
An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.
CVE-2018-21253
- EPSS 0.15%
- Veröffentlicht 19.06.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:03:17
An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user.
CVE-2018-21254
- EPSS 0.15%
- Veröffentlicht 19.06.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:03:17
An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command.