Show filters
386 Total Results
Displaying 131-140 of 386
Sort by:
Attacker Value
Unknown
CVE-2023-43754
Disclosure Date: November 27, 2023 (last updated December 02, 2023)
Mattermost fails to check whether the “Allow users to view archived channels” setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if the “Allow users to view archived channels” setting is disabled.
0
Attacker Value
Unknown
CVE-2023-40703
Disclosure Date: November 27, 2023 (last updated December 02, 2023)
Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a attacker to consume excessive resources, possibly leading to Denial of Service, by patching the field of a block using a specially crafted string.
0
Attacker Value
Unknown
CVE-2023-35075
Disclosure Date: November 27, 2023 (last updated December 01, 2023)
Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though.
0
Attacker Value
Unknown
CVE-2023-47865
Disclosure Date: November 27, 2023 (last updated December 02, 2023)
Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled
0
Attacker Value
Unknown
CVE-2023-5969
Disclosure Date: November 06, 2023 (last updated November 15, 2023)
Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items.
0
Attacker Value
Unknown
CVE-2023-5968
Disclosure Date: November 06, 2023 (last updated November 15, 2023)
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
0
Attacker Value
Unknown
CVE-2023-5967
Disclosure Date: November 06, 2023 (last updated November 15, 2023)
Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin
0
Attacker Value
Unknown
CVE-2023-5920
Disclosure Date: November 02, 2023 (last updated November 10, 2023)
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.
0
Attacker Value
Unknown
CVE-2023-5876
Disclosure Date: November 02, 2023 (last updated November 10, 2023)
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
0
Attacker Value
Unknown
CVE-2023-5875
Disclosure Date: November 02, 2023 (last updated November 10, 2023)
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server
0