Mattermost

Mattermost Desktop

18 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Published 17.03.2025 14:19:51
  • Last modified 25.09.2025 19:14:25

Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.

  • EPSS 0.1%
  • Published 16.09.2024 15:15:16
  • Last modified 01.11.2024 14:20:56

Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.

  • EPSS 0.11%
  • Published 16.09.2024 15:15:16
  • Last modified 01.11.2024 14:20:22

Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.

  • EPSS 0.08%
  • Published 16.09.2024 07:15:02
  • Last modified 20.09.2024 13:59:01

Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on ...

  • EPSS 0.25%
  • Published 14.06.2024 09:15:10
  • Last modified 21.11.2024 09:23:22

Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.

  • EPSS 0.03%
  • Published 14.06.2024 09:15:09
  • Last modified 21.11.2024 09:21:59

Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.

  • EPSS 0.17%
  • Published 02.11.2023 09:15:08
  • Last modified 21.11.2024 08:42:41

Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server

  • EPSS 0.08%
  • Published 02.11.2023 09:15:08
  • Last modified 21.11.2024 08:42:46

Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.

  • EPSS 0.12%
  • Published 02.11.2023 09:15:08
  • Last modified 21.11.2024 08:42:41

Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.

  • EPSS 0.07%
  • Published 17.10.2023 10:15:10
  • Last modified 21.11.2024 08:41:33

Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.