Mattermost

Mattermost

245 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 06.11.2023 16:15:42
  • Zuletzt bearbeitet 21.11.2024 08:42:53

Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items.

  • EPSS 0.09%
  • Veröffentlicht 17.10.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:41:56

Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel. 

  • EPSS 0.23%
  • Veröffentlicht 02.10.2023 11:15:50
  • Zuletzt bearbeitet 21.11.2024 08:41:12

Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled

  • EPSS 0.03%
  • Veröffentlicht 29.09.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:41:12

Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user edit permissions to manage/update bots.

  • EPSS 0.18%
  • Veröffentlicht 29.09.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:41:16

Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.

  • EPSS 0.03%
  • Veröffentlicht 29.09.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:41:16

Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager

  • EPSS 0.05%
  • Veröffentlicht 29.09.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:41:16

Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

  • EPSS 0.23%
  • Veröffentlicht 29.09.2023 10:15:10
  • Zuletzt bearbeitet 21.11.2024 08:41:16

Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becomi...

  • EPSS 0.16%
  • Veröffentlicht 11.08.2023 07:15:10
  • Zuletzt bearbeitet 21.11.2024 08:34:24

Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

  • EPSS 0.25%
  • Veröffentlicht 11.08.2023 07:15:09
  • Zuletzt bearbeitet 21.11.2024 08:34:24

Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message