CVE-2024-8071
- EPSS 0.11%
- Veröffentlicht 22.08.2024 07:15:04
- Zuletzt bearbeitet 23.08.2024 15:34:53
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update...
CVE-2024-32939
- EPSS 0.16%
- Veröffentlicht 22.08.2024 07:15:03
- Zuletzt bearbeitet 23.08.2024 16:17:54
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be...
CVE-2024-39810
- EPSS 0.15%
- Veröffentlicht 22.08.2024 07:15:03
- Zuletzt bearbeitet 23.08.2024 16:16:36
Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path fiel...
CVE-2024-39836
- EPSS 0.39%
- Veröffentlicht 22.08.2024 07:15:03
- Zuletzt bearbeitet 23.08.2024 16:16:18
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be ...
CVE-2024-39274
- EPSS 0.2%
- Veröffentlicht 01.08.2024 15:15:12
- Zuletzt bearbeitet 23.08.2024 14:39:29
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the sync message is a shared channel, when shared channels are enabled, which allows a malicious remote t...
CVE-2024-39777
- EPSS 0.2%
- Veröffentlicht 01.08.2024 15:15:12
- Zuletzt bearbeitet 23.08.2024 14:36:48
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with th...
CVE-2024-39832
- EPSS 0.26%
- Veröffentlicht 01.08.2024 15:15:12
- Zuletzt bearbeitet 23.08.2024 14:35:13
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels ...
CVE-2024-29977
- EPSS 0.16%
- Veröffentlicht 01.08.2024 15:15:11
- Zuletzt bearbeitet 23.08.2024 14:52:19
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts
CVE-2024-36492
- EPSS 0.21%
- Veröffentlicht 01.08.2024 15:15:11
- Zuletzt bearbeitet 23.08.2024 14:51:08
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing users in shared channels. which allows a malicious remote to overwrite an existing local user.
CVE-2024-6428
- EPSS 0.06%
- Veröffentlicht 03.07.2024 09:15:08
- Zuletzt bearbeitet 21.11.2024 09:49:38
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-def...