CVE-2025-1398
- EPSS 0.02%
- Veröffentlicht 17.03.2025 14:19:51
- Zuletzt bearbeitet 25.09.2025 19:14:25
Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.
CVE-2024-45835
- EPSS 0.1%
- Veröffentlicht 16.09.2024 15:15:16
- Zuletzt bearbeitet 01.11.2024 14:20:56
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
CVE-2024-39772
- EPSS 0.11%
- Veröffentlicht 16.09.2024 15:15:16
- Zuletzt bearbeitet 01.11.2024 14:20:22
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
CVE-2024-39613
- EPSS 0.08%
- Veröffentlicht 16.09.2024 07:15:02
- Zuletzt bearbeitet 20.09.2024 13:59:01
Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on ...
CVE-2024-37182
- EPSS 0.25%
- Veröffentlicht 14.06.2024 09:15:10
- Zuletzt bearbeitet 21.11.2024 09:23:22
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
CVE-2024-36287
- EPSS 0.03%
- Veröffentlicht 14.06.2024 09:15:09
- Zuletzt bearbeitet 21.11.2024 09:21:59
Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.
CVE-2023-5875
- EPSS 0.17%
- Veröffentlicht 02.11.2023 09:15:08
- Zuletzt bearbeitet 21.11.2024 08:42:41
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server
CVE-2023-5920
- EPSS 0.08%
- Veröffentlicht 02.11.2023 09:15:08
- Zuletzt bearbeitet 21.11.2024 08:42:46
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.
CVE-2023-5876
- EPSS 0.12%
- Veröffentlicht 02.11.2023 09:15:08
- Zuletzt bearbeitet 21.11.2024 08:42:41
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
CVE-2023-5339
- EPSS 0.07%
- Veröffentlicht 17.10.2023 10:15:10
- Zuletzt bearbeitet 21.11.2024 08:41:33
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.