CVE-2023-2785
- EPSS 0.12%
- Veröffentlicht 16.06.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:17
Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service
CVE-2023-2792
- EPSS 0.22%
- Veröffentlicht 16.06.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:17
Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg command.
CVE-2023-2793
- EPSS 0.23%
- Veröffentlicht 16.06.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:18
Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an attacker to cause a denial-of-service by a linking to a specially crafted webpage in a message.
CVE-2023-2797
- EPSS 0.47%
- Veröffentlicht 16.06.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:18
Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink on a channel.
CVE-2023-2831
- EPSS 0.12%
- Veröffentlicht 16.06.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:22
Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Service by sending a message containing a large number of escaped characters.
CVE-2023-2791
- EPSS 0.12%
- Veröffentlicht 16.06.2023 09:15:10
- Zuletzt bearbeitet 21.11.2024 07:59:17
When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated attacker to edit an arbitrary channel post.
CVE-2023-2783
- EPSS 0.1%
- Veröffentlicht 16.06.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:16
Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.
CVE-2023-2784
- EPSS 0.06%
- Veröffentlicht 16.06.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:17
Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install requests to the Apps.
CVE-2023-2786
- EPSS 0.08%
- Veröffentlicht 16.06.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:17
Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.
CVE-2023-2787
- EPSS 0.14%
- Veröffentlicht 16.06.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:17
Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message threads API.