Mattermost

Mattermost

180 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Veröffentlicht 28.11.2024 10:15:06
  • Zuletzt bearbeitet 01.10.2025 18:25:03

Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registra...

  • EPSS 0.26%
  • Veröffentlicht 29.10.2024 09:15:07
  • Zuletzt bearbeitet 29.09.2025 14:47:01

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in...

  • EPSS 0.13%
  • Veröffentlicht 29.10.2024 08:15:12
  • Zuletzt bearbeitet 29.09.2025 14:47:32

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.

  • EPSS 0.1%
  • Veröffentlicht 29.10.2024 08:15:11
  • Zuletzt bearbeitet 30.09.2025 17:09:36

Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.

  • EPSS 0.08%
  • Veröffentlicht 28.10.2024 15:15:04
  • Zuletzt bearbeitet 05.11.2024 17:03:22

Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.

  • EPSS 0.1%
  • Veröffentlicht 26.09.2024 15:15:18
  • Zuletzt bearbeitet 29.09.2025 13:50:51

Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have not been linked to a post which allows an attacker to view them in channels that they are a member of.

  • EPSS 0.15%
  • Veröffentlicht 23.08.2024 08:15:04
  • Zuletzt bearbeitet 23.08.2024 16:18:28

Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.

  • EPSS 0.19%
  • Veröffentlicht 22.08.2024 07:15:04
  • Zuletzt bearbeitet 23.08.2024 16:09:31

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in User Ma...

  • EPSS 0.33%
  • Veröffentlicht 22.08.2024 07:15:04
  • Zuletzt bearbeitet 23.08.2024 16:04:26

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their ac...

  • EPSS 0.22%
  • Veröffentlicht 22.08.2024 07:15:04
  • Zuletzt bearbeitet 23.08.2024 15:35:12

Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any user.