CVE-2024-36255
- EPSS 0.21%
- Veröffentlicht 26.05.2024 14:15:10
- Zuletzt bearbeitet 30.09.2025 15:29:54
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post...
CVE-2024-5270
- EPSS 0.21%
- Veröffentlicht 26.05.2024 14:15:10
- Zuletzt bearbeitet 30.09.2025 15:47:34
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is enabled when a user requests to switch from SAML to Email. This allows the user to switch their authentic...
CVE-2024-5272
- EPSS 0.28%
- Veröffentlicht 26.05.2024 14:15:10
- Zuletzt bearbeitet 30.09.2025 15:48:21
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the...
CVE-2024-32045
- EPSS 0.27%
- Veröffentlicht 26.05.2024 14:15:09
- Zuletzt bearbeitet 30.09.2025 15:24:46
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channels they were...
CVE-2024-34029
- EPSS 0.42%
- Veröffentlicht 26.05.2024 14:15:09
- Zuletzt bearbeitet 30.09.2025 15:26:42
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups/<group-id>/channels/<channel-id>/link endpoint which allows a user to learn the members of an AD/LDAP group that...
CVE-2024-34152
- EPSS 0.36%
- Veröffentlicht 26.05.2024 14:15:09
- Zuletzt bearbeitet 30.09.2025 15:27:40
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allows a guest to get the metadata of a public playbook run that linked to the channel they are guest via sending an RHSRuns GraphQL qu...
CVE-2024-36241
- EPSS 0.36%
- Veröffentlicht 26.05.2024 14:15:09
- Zuletzt bearbeitet 30.09.2025 15:28:53
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook add slash command
CVE-2024-29215
- EPSS 0.19%
- Veröffentlicht 26.05.2024 14:15:08
- Zuletzt bearbeitet 08.07.2025 18:02:30
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access control which allows a user to run a slash command in a channel they are not a member of via linking a playbook run to that channel and ...
CVE-2024-31859
- EPSS 0.11%
- Veröffentlicht 26.05.2024 14:15:08
- Zuletzt bearbeitet 30.09.2025 15:20:13
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel admin
CVE-2024-4198
- EPSS 0.14%
- Veröffentlicht 26.04.2024 09:15:13
- Zuletzt bearbeitet 12.05.2025 13:45:11
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.