Mattermost

Mattermost Server

374 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 24.12.2025 08:15:46
  • Zuletzt bearbeitet 31.12.2025 18:55:29

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jir...

  • EPSS 0.04%
  • Veröffentlicht 24.12.2025 08:15:45
  • Zuletzt bearbeitet 31.12.2025 18:56:27

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to...

  • EPSS 0.12%
  • Veröffentlicht 22.12.2025 11:24:55
  • Zuletzt bearbeitet 29.12.2025 18:47:45

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin,...

  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 18:14:13
  • Zuletzt bearbeitet 29.12.2025 18:46:13

Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an a...

  • EPSS 0.1%
  • Veröffentlicht 17.12.2025 18:14:10
  • Zuletzt bearbeitet 29.12.2025 18:44:33

Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to crash Calls plug-in via sending malformed request.

  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 12:19:17
  • Zuletzt bearbeitet 29.12.2025 18:55:05

Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.

  • EPSS 0.06%
  • Veröffentlicht 17.12.2025 12:11:25
  • Zuletzt bearbeitet 29.12.2025 18:50:47

Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary Git...

  • EPSS 0.02%
  • Veröffentlicht 17.12.2025 12:07:37
  • Zuletzt bearbeitet 29.12.2025 18:51:51

Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject message...

  • EPSS 0.04%
  • Veröffentlicht 02.12.2025 09:28:44
  • Zuletzt bearbeitet 03.12.2025 20:57:20

Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe t...

  • EPSS 0.03%
  • Veröffentlicht 01.12.2025 19:51:46
  • Zuletzt bearbeitet 05.12.2025 15:26:22

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by ...