Mattermost

Mattermost

180 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 29.09.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:41:16

Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager

  • EPSS 0.05%
  • Veröffentlicht 29.09.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:41:16

Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

  • EPSS 0.17%
  • Veröffentlicht 29.09.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:41:16

Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becomi...

  • EPSS 0.14%
  • Veröffentlicht 11.08.2023 07:15:10
  • Zuletzt bearbeitet 21.11.2024 08:34:24

Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

  • EPSS 0.25%
  • Veröffentlicht 11.08.2023 07:15:09
  • Zuletzt bearbeitet 21.11.2024 08:34:24

Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message

  • EPSS 0.09%
  • Veröffentlicht 11.08.2023 07:15:09
  • Zuletzt bearbeitet 21.11.2024 08:34:24

Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.

  • EPSS 0.03%
  • Veröffentlicht 11.08.2023 07:15:09
  • Zuletzt bearbeitet 21.11.2024 08:34:24

Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name.

  • EPSS 0.22%
  • Veröffentlicht 17.07.2023 16:15:11
  • Zuletzt bearbeitet 21.11.2024 08:17:40

Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection.

  • EPSS 0.12%
  • Veröffentlicht 16.06.2023 10:15:09
  • Zuletzt bearbeitet 21.11.2024 07:59:17

Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service

  • EPSS 0.22%
  • Veröffentlicht 16.06.2023 10:15:09
  • Zuletzt bearbeitet 21.11.2024 07:59:17

Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg command.