Total
198 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-18887 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 5.0 MEDIUM | 5.3 MEDIUM |
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members. | |||||
CVE-2017-18889 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 4.0 MEDIUM | 4.3 MEDIUM |
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could create fictive system-message posts via webhooks and slash commands, in the v3 or v4 REST API. | |||||
CVE-2017-18915 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoint access. | |||||
CVE-2018-21255 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 4.0 MEDIUM | 4.3 MEDIUM |
An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to modify that channel. | |||||
CVE-2018-21250 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 4.3 MEDIUM | 6.5 MEDIUM |
An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consumption) via crafted image dimensions. | |||||
CVE-2019-20883 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 3.5 LOW | 4.3 MEDIUM |
An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Users can pin or unpin a post. | |||||
CVE-2016-11072 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 6.4 MEDIUM | 6.5 MEDIUM |
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled. | |||||
CVE-2018-21251 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body. | |||||
CVE-2017-18893 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS. | |||||
CVE-2017-18870 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 3.5 LOW | 4.3 MEDIUM |
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case. | |||||
CVE-2017-18910 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 4.0 MEDIUM | 4.3 MEDIUM |
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links. | |||||
CVE-2017-18874 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 5.5 MEDIUM | 6.5 MEDIUM |
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal. | |||||
CVE-2017-18912 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file. | |||||
CVE-2016-11073 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting. | |||||
CVE-2017-18876 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 4.0 MEDIUM | 4.9 MEDIUM |
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file. | |||||
CVE-2017-18894 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 5.5 MEDIUM | 8.1 HIGH |
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover. | |||||
CVE-2017-18896 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 5.0 MEDIUM | 5.3 MEDIUM |
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint. | |||||
CVE-2016-11068 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 5.0 MEDIUM | 5.3 MEDIUM |
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection. | |||||
CVE-2017-18918 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 4.0 MEDIUM | 4.9 MEDIUM |
An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate at an arbitrary pathname. | |||||
CVE-2017-18871 | 1 Mattermost | 1 Mattermost Server | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denial of service (application crash) via an @ character before a JavaScript field name. |