Mattermost

Mattermost

180 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 22.02%
  • Published 24.02.2025 08:15:10
  • Last modified 02.10.2025 18:19:20

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a...

  • EPSS 0.05%
  • Published 24.02.2025 08:15:09
  • Last modified 01.10.2025 18:02:32

Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.

  • EPSS 0.05%
  • Published 14.02.2025 18:15:23
  • Last modified 29.09.2025 18:11:58

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.

  • EPSS 0.15%
  • Published 16.01.2025 19:15:30
  • Last modified 24.09.2025 16:42:32

Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.

  • EPSS 0.25%
  • Published 16.01.2025 19:15:29
  • Last modified 01.10.2025 17:54:41

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via cre...

  • EPSS 0.12%
  • Published 16.01.2025 18:15:28
  • Last modified 24.09.2025 16:46:59

Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.

  • EPSS 0.31%
  • Published 16.01.2025 00:15:25
  • Last modified 24.09.2025 16:47:36

Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment

  • EPSS 0.25%
  • Published 15.01.2025 17:15:19
  • Last modified 30.09.2025 15:51:23

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

  • EPSS 0.25%
  • Published 15.01.2025 17:15:19
  • Last modified 01.10.2025 18:20:36

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

  • EPSS 0.15%
  • Published 15.01.2025 17:15:19
  • Last modified 25.09.2025 19:14:15

Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.