Show filters
386 Total Results
Displaying 141-150 of 386
Sort by:
Attacker Value
Unknown
CVE-2023-5522
Disclosure Date: October 17, 2023 (last updated October 25, 2023)
Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel.
0
Attacker Value
Unknown
CVE-2023-5339
Disclosure Date: October 17, 2023 (last updated October 25, 2023)
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.
0
Attacker Value
Unknown
CVE-2023-5333
Disclosure Date: October 09, 2023 (last updated October 13, 2023)
Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.
0
Attacker Value
Unknown
CVE-2023-5331
Disclosure Date: October 09, 2023 (last updated October 13, 2023)
Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exposing unauthorized file information.
0
Attacker Value
Unknown
CVE-2023-5330
Disclosure Date: October 09, 2023 (last updated October 13, 2023)
Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.
0
Attacker Value
Unknown
CVE-2023-5160
Disclosure Date: October 02, 2023 (last updated October 09, 2023)
Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled
0
Attacker Value
Unknown
CVE-2023-5196
Disclosure Date: September 29, 2023 (last updated October 08, 2023)
Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.
0
Attacker Value
Unknown
CVE-2023-5195
Disclosure Date: September 29, 2023 (last updated October 08, 2023)
Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of
0
Attacker Value
Unknown
CVE-2023-5194
Disclosure Date: September 29, 2023 (last updated October 08, 2023)
Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager
0
Attacker Value
Unknown
CVE-2023-5193
Disclosure Date: September 29, 2023 (last updated October 08, 2023)
Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.
0