CVE-2024-11358
- EPSS 0.05%
- Veröffentlicht 16.12.2024 17:15:07
- Zuletzt bearbeitet 24.09.2025 19:39:33
Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.
CVE-2024-54083
- EPSS 0.52%
- Veröffentlicht 16.12.2024 08:15:05
- Zuletzt bearbeitet 30.09.2025 15:49:33
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a...
CVE-2024-54682
- EPSS 0.2%
- Veröffentlicht 16.12.2024 08:15:05
- Zuletzt bearbeitet 30.09.2025 15:50:38
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin.
CVE-2024-48872
- EPSS 0.06%
- Veröffentlicht 16.12.2024 08:15:04
- Zuletzt bearbeitet 15.10.2025 14:13:31
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which allows an attacker to bypass of "Max failed attempts" restriction and se...
CVE-2024-12247
- EPSS 0.08%
- Veröffentlicht 05.12.2024 16:15:25
- Zuletzt bearbeitet 01.10.2025 18:21:08
Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.
CVE-2024-11599
- EPSS 0.07%
- Veröffentlicht 28.11.2024 10:15:06
- Zuletzt bearbeitet 01.10.2025 18:25:03
Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registra...
CVE-2024-47401
- EPSS 0.18%
- Veröffentlicht 29.10.2024 09:15:07
- Zuletzt bearbeitet 29.09.2025 14:47:01
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in...
CVE-2024-50052
- EPSS 0.26%
- Veröffentlicht 29.10.2024 08:15:12
- Zuletzt bearbeitet 29.09.2025 14:47:32
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.
CVE-2024-10241
- EPSS 0.36%
- Veröffentlicht 29.10.2024 08:15:11
- Zuletzt bearbeitet 30.09.2025 17:09:36
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
CVE-2024-10214
- EPSS 0.36%
- Veröffentlicht 28.10.2024 15:15:04
- Zuletzt bearbeitet 05.11.2024 17:03:22
Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.