Skip to main content

Vendor archive

mattermost CVEs

Beta · best-effort

602 CVEs tagged to vendor mattermost21 Critical, 88 High, 367 Medium, 126 Low, 0 Unrated.

CVE-2019-20883

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Users can pin or unpin a post.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20882

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20880

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20879

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20878

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20877

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20876

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20875

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21265

Published Jun 19, 2020

An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21263

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-21262

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX text.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-21261

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the team invite_id, which leads to unintended excessive invitat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21260

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent during certain user-management operations, violating user priv…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-21259

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21258

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-21257

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash com…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21255

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to modify that channel.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21254

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21253

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21251

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-21250

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consumption) via crafted image dimens…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18877

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 526-550 of 602 CVEsPage 22 of 25