Mattermost

Mattermost

202 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 21.08.2025 08:15:30
  • Zuletzt bearbeitet 22.08.2025 18:09:17

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the...

  • EPSS 0.05%
  • Veröffentlicht 21.08.2025 08:15:30
  • Zuletzt bearbeitet 22.08.2025 18:09:17

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remote cluster upload sessions which allows a system admin to upload non-attachment file types via shared...

  • EPSS 0.06%
  • Veröffentlicht 21.08.2025 07:51:37
  • Zuletzt bearbeitet 25.08.2025 14:56:33

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path traversal sequences in template file destination paths, which allows a system admin to perform path traversal attacks via malicious pat...

  • EPSS 0.04%
  • Veröffentlicht 21.08.2025 07:31:01
  • Zuletzt bearbeitet 22.08.2025 18:09:17

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team Members to Guests via the PUT /api/v4/teams/team-id/members/user-id/schemeRoles...

  • EPSS 0.04%
  • Veröffentlicht 21.08.2025 07:28:37
  • Zuletzt bearbeitet 29.10.2025 18:40:16

Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions

  • EPSS 0.04%
  • Veröffentlicht 21.08.2025 07:15:27
  • Zuletzt bearbeitet 22.08.2025 18:09:17

Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts

  • EPSS 0.06%
  • Veröffentlicht 21.08.2025 07:11:43
  • Zuletzt bearbeitet 22.08.2025 18:09:17

Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path trave...

  • EPSS 0.03%
  • Veröffentlicht 18.07.2025 11:39:46
  • Zuletzt bearbeitet 14.10.2025 14:32:24

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the in...

  • EPSS 0.05%
  • Veröffentlicht 18.07.2025 09:09:22
  • Zuletzt bearbeitet 02.10.2025 19:49:31

Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.

  • EPSS 0.04%
  • Veröffentlicht 18.07.2025 08:48:02
  • Zuletzt bearbeitet 02.10.2025 19:49:18

Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't hav...