Show filters
229 Total Results
Displaying 1-10 of 229
Sort by:
Attacker Value
Unknown
CVE-2024-52032
Disclosure Date: November 09, 2024 (last updated November 15, 2024)
Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to get private channels names of channels that they are not a member of, when Elasticsearch v8 was enabled.
0
Attacker Value
Unknown
CVE-2024-42000
Disclosure Date: November 09, 2024 (last updated November 15, 2024)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels which allows a User or System Manager, with "Read Groups" permission but with no access for channels to retrieve details about private channels that they were not a member of by sending a request to /api/v4/channels.
0
Attacker Value
Unknown
CVE-2024-36250
Disclosure Date: November 09, 2024 (last updated November 15, 2024)
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
0
Attacker Value
Unknown
CVE-2024-46872
Disclosure Date: October 29, 2024 (last updated November 09, 2024)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks
0
Attacker Value
Unknown
CVE-2024-47145
Disclosure Date: September 26, 2024 (last updated September 27, 2024)
Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.
0
Attacker Value
Unknown
CVE-2024-47003
Disclosure Date: September 26, 2024 (last updated September 27, 2024)
Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker to send a non-string value as the message of a permalink post and crash the frontend.
0
Attacker Value
Unknown
CVE-2024-45843
Disclosure Date: September 26, 2024 (last updated September 27, 2024)
Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.
0
Attacker Value
Unknown
CVE-2024-42406
Disclosure Date: September 26, 2024 (last updated October 01, 2024)
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files.
0
Attacker Value
Unknown
CVE-2024-43780
Disclosure Date: August 22, 2024 (last updated October 17, 2024)
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.
0
Attacker Value
Unknown
CVE-2024-42497
Disclosure Date: August 22, 2024 (last updated October 17, 2024)
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems manager role with read-only access to teams to perform write operations on teams.
0