Mattermost

Mattermost

214 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 17.03.2025 14:19:51
  • Zuletzt bearbeitet 25.09.2025 19:14:25

Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.

  • EPSS 0.28%
  • Veröffentlicht 24.02.2025 08:15:10
  • Zuletzt bearbeitet 18.08.2025 18:22:38

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicating a board, which allows a user to read any arbitrary file on the system via duplicating a specially...

  • EPSS 0.27%
  • Veröffentlicht 24.02.2025 08:15:10
  • Zuletzt bearbeitet 01.10.2025 18:03:04

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards reordering which allows an attacker to retrieve data from the database, via a SQL injection when reo...

  • EPSS 0.03%
  • Veröffentlicht 24.02.2025 08:15:10
  • Zuletzt bearbeitet 01.10.2025 18:03:20

Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when the "Allow users to view archived channels" is disabled which allows a user to expo...

  • EPSS 29.29%
  • Veröffentlicht 24.02.2025 08:15:10
  • Zuletzt bearbeitet 02.10.2025 18:19:20

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a...

  • EPSS 0.08%
  • Veröffentlicht 24.02.2025 08:15:09
  • Zuletzt bearbeitet 01.10.2025 18:02:32

Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.

  • EPSS 0.11%
  • Veröffentlicht 14.02.2025 18:15:23
  • Zuletzt bearbeitet 29.09.2025 18:11:58

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.

  • EPSS 0.15%
  • Veröffentlicht 16.01.2025 19:15:30
  • Zuletzt bearbeitet 24.09.2025 16:42:32

Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.

  • EPSS 0.26%
  • Veröffentlicht 16.01.2025 19:15:29
  • Zuletzt bearbeitet 01.10.2025 17:54:41

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via cre...

  • EPSS 0.15%
  • Veröffentlicht 16.01.2025 18:15:28
  • Zuletzt bearbeitet 24.09.2025 16:46:59

Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.