CVE-2024-42411
- EPSS 0.28%
- Veröffentlicht 22.08.2024 07:15:04
- Zuletzt bearbeitet 23.08.2024 16:04:26
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their ac...
CVE-2024-43813
- EPSS 0.22%
- Veröffentlicht 22.08.2024 07:15:04
- Zuletzt bearbeitet 23.08.2024 15:35:12
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any user.
CVE-2024-8071
- EPSS 0.09%
- Veröffentlicht 22.08.2024 07:15:04
- Zuletzt bearbeitet 23.08.2024 15:34:53
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update...
CVE-2024-32939
- EPSS 0.21%
- Veröffentlicht 22.08.2024 07:15:03
- Zuletzt bearbeitet 23.08.2024 16:17:54
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be...
CVE-2024-39810
- EPSS 0.28%
- Veröffentlicht 22.08.2024 07:15:03
- Zuletzt bearbeitet 23.08.2024 16:16:36
Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path fiel...
CVE-2024-39836
- EPSS 0.39%
- Veröffentlicht 22.08.2024 07:15:03
- Zuletzt bearbeitet 23.08.2024 16:16:18
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be ...
CVE-2024-39274
- EPSS 0.21%
- Veröffentlicht 01.08.2024 15:15:12
- Zuletzt bearbeitet 23.08.2024 14:39:29
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the sync message is a shared channel, when shared channels are enabled, which allows a malicious remote t...
CVE-2024-39777
- EPSS 0.2%
- Veröffentlicht 01.08.2024 15:15:12
- Zuletzt bearbeitet 23.08.2024 14:36:48
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with th...
CVE-2024-39832
- EPSS 0.26%
- Veröffentlicht 01.08.2024 15:15:12
- Zuletzt bearbeitet 23.08.2024 14:35:13
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels ...
CVE-2024-29977
- EPSS 0.16%
- Veröffentlicht 01.08.2024 15:15:11
- Zuletzt bearbeitet 23.08.2024 14:52:19
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts