Mattermost

Mattermost Server

473 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 22.06.2026 13:34:21
  • Zuletzt bearbeitet 23.06.2026 20:50:51

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler, which allows any authenticate...

  • EPSS 0.28%
  • Veröffentlicht 25.05.2026 07:10:23
  • Zuletzt bearbeitet 23.07.2026 17:10:00

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil elements from outgoing webhook attachment payloads before processing, which allows an authenticated user to cause a denial of service (se...

  • EPSS 0.14%
  • Veröffentlicht 22.05.2026 16:26:04
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying th...

  • EPSS 0.17%
  • Veröffentlicht 22.05.2026 10:28:47
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent notifications which allows authenticated user to crash the server via timing the creation of persiste...

  • EPSS 0.15%
  • Veröffentlicht 22.05.2026 10:27:02
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via cr...

  • EPSS 0.25%
  • Veröffentlicht 22.05.2026 10:25:17
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supplied input in API request handlers which allows an authenticated attacker to crash the plugin process via a crafted HTTP request t...

  • EPSS 0.18%
  • Veröffentlicht 22.05.2026 10:23:20
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team member data when returned via API to users without elevated permissions which allows a user without permissions to get data about team...

  • EPSS 0.34%
  • Veröffentlicht 22.05.2026 10:22:01
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate msgpack-encoded WebSocket frames before memory allocation which allows an unauthenticated remote attacker to crash the server proc...

  • EPSS 0.25%
  • Veröffentlicht 22.05.2026 10:20:43
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP endpoints which allows an attacker to cause a denial of service via crafted oversized HTTP requests....

  • EPSS 0.25%
  • Veröffentlicht 22.05.2026 10:18:49
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the TIFF IFD offset in the image header before allocating memory, which allows authenticated users with file upload or po...