Filtered by vendor Mattermost
Subscribe
Total
320 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-37859 | 1 Mattermost | 1 Mattermost | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost. | |||||
CVE-2019-20863 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted. | |||||
CVE-2016-11083 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window. | |||||
CVE-2017-18908 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-mail address. | |||||
CVE-2018-21265 | 1 Mattermost | 1 Mattermost Desktop | 2024-02-28 | 5.0 MEDIUM | 5.3 MEDIUM |
An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications). | |||||
CVE-2017-18871 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denial of service (application crash) via an @ character before a JavaScript field name. | |||||
CVE-2016-11072 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 6.4 MEDIUM | 6.5 MEDIUM |
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled. | |||||
CVE-2016-11073 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting. | |||||
CVE-2017-18870 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 3.5 LOW | 4.3 MEDIUM |
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case. | |||||
CVE-2017-18911 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 6.4 MEDIUM | 9.1 CRITICAL |
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server. | |||||
CVE-2016-11078 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 4.0 MEDIUM | 6.5 MEDIUM |
An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI. | |||||
CVE-2018-21260 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 4.0 MEDIUM | 2.7 LOW |
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent during certain user-management operations, violating user privacy. | |||||
CVE-2016-11064 | 1 Mattermost | 1 Mattermost Desktop | 2024-02-28 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection. | |||||
CVE-2016-11074 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused. | |||||
CVE-2020-13891 | 1 Mattermost | 1 Mattermost | 2024-02-28 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in Mattermost Mobile Apps before 1.31.2 on iOS. Unintended third-party servers could sometimes obtain authorization tokens, aka MMSA-2020-0022. | |||||
CVE-2020-14457 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 5.0 MEDIUM | 5.3 MEDIUM |
An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the update_team WebSocket event, aka MMSA-2020-0012. | |||||
CVE-2017-18882 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data. | |||||
CVE-2017-18874 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 5.5 MEDIUM | 6.5 MEDIUM |
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal. | |||||
CVE-2017-18898 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 5.0 MEDIUM | 5.3 MEDIUM |
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially cause a web browser to hang. | |||||
CVE-2020-14458 | 1 Mattermost | 1 Mattermost Server | 2024-02-28 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel by name" API, aka MMSA-2020-0004. |