Mattermost

Mattermost

202 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 13.10.2025 20:15:33
  • Zuletzt bearbeitet 29.10.2025 13:34:07

Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.

  • EPSS 0.02%
  • Veröffentlicht 10.10.2025 11:15:15
  • Zuletzt bearbeitet 02.12.2025 10:16:00

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.

  • EPSS 0.02%
  • Veröffentlicht 19.09.2025 19:36:14
  • Zuletzt bearbeitet 25.09.2025 20:14:59

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration

  • EPSS 0.05%
  • Veröffentlicht 19.09.2025 19:22:00
  • Zuletzt bearbeitet 25.09.2025 20:16:04

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory path configuration which allows admin users to execute arbitrary code via malicious plugin upload to pre...

  • EPSS 0.04%
  • Veröffentlicht 15.09.2025 10:28:17
  • Zuletzt bearbeitet 16.09.2025 16:00:26

Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cook...

  • EPSS 0.04%
  • Veröffentlicht 15.09.2025 10:22:30
  • Zuletzt bearbeitet 16.09.2025 15:59:24

Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted OAuth login URLs

  • EPSS 0.04%
  • Veröffentlicht 15.09.2025 10:15:32
  • Zuletzt bearbeitet 20.09.2025 02:52:38

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This...

  • EPSS 0.02%
  • Veröffentlicht 15.09.2025 10:15:32
  • Zuletzt bearbeitet 16.09.2025 15:58:12

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to properly validate cache keys for link metadata which allows authenticated users to access unauthorized posts and poison link previ...

  • EPSS 0.1%
  • Veröffentlicht 21.08.2025 17:01:43
  • Zuletzt bearbeitet 01.10.2025 20:23:12

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature.

  • EPSS 0.07%
  • Veröffentlicht 21.08.2025 17:01:42
  • Zuletzt bearbeitet 02.10.2025 19:49:46

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs.