CVE-2024-32945
- EPSS 0.44%
- Veröffentlicht 15.07.2024 09:15:02
- Zuletzt bearbeitet 21.11.2024 09:16:05
Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
CVE-2024-3872
- EPSS 0.5%
- Veröffentlicht 16.04.2024 09:15:08
- Zuletzt bearbeitet 21.01.2025 16:57:31
Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.
CVE-2024-24975
- EPSS 0.12%
- Veröffentlicht 15.03.2024 09:15:06
- Zuletzt bearbeitet 21.01.2025 18:41:23
Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the syntax highlighter, allowing an attacker to send a very large code block and crash the mobile app.
CVE-2019-20852
- EPSS 0.32%
- Veröffentlicht 19.06.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:39:32
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content).
CVE-2020-14451
- EPSS 0.32%
- Veröffentlicht 19.06.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:03:18
An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local Storage to remain after a logout, aka MMSA-2020-0013.
CVE-2020-14449
- EPSS 0.32%
- Veröffentlicht 19.06.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:03:18
An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to third-party servers, aka MMSA-2020-0018.
CVE-2019-20848
- EPSS 0.24%
- Veröffentlicht 19.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:39:31
An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies.
CVE-2019-20850
- EPSS 0.24%
- Veröffentlicht 19.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:39:31
An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.
CVE-2019-20849
- EPSS 0.24%
- Veröffentlicht 19.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:39:31
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.