CVE-2018-21263
- EPSS 0.34%
- Veröffentlicht 19.06.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:03:19
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response.
CVE-2019-20875
- EPSS 0.2%
- Veröffentlicht 19.06.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:39:35
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.
CVE-2019-20876
- EPSS 0.35%
- Veröffentlicht 19.06.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:39:35
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.
CVE-2019-20877
- EPSS 0.24%
- Veröffentlicht 19.06.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:39:35
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.
CVE-2019-20878
- EPSS 0.23%
- Veröffentlicht 19.06.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:39:35
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled.
CVE-2019-20879
- EPSS 0.15%
- Veröffentlicht 19.06.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:39:36
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry.
CVE-2019-20880
- EPSS 0.39%
- Veröffentlicht 19.06.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:39:36
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph.
CVE-2019-20881
- EPSS 0.28%
- Veröffentlicht 19.06.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:39:36
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
CVE-2019-20882
- EPSS 0.2%
- Veröffentlicht 19.06.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:39:36
An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.
CVE-2019-20883
- EPSS 0.23%
- Veröffentlicht 19.06.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:39:36
An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Users can pin or unpin a post.