Show filters
381 Total Results
Displaying 21-30 of 381
Sort by:
Attacker Value
Unknown

CVE-2024-42000

Disclosure Date: November 09, 2024 (last updated November 15, 2024)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels  which allows a User or System Manager, with "Read Groups" permission but with no access for channels to retrieve details about private channels that they were not a member of by sending a request to /api/v4/channels.
Attacker Value
Unknown

CVE-2024-36250

Disclosure Date: November 09, 2024 (last updated November 15, 2024)
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
Attacker Value
Unknown

CVE-2024-47401

Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn could cause the application to crash by sending a specially crafted request to Playbooks.
0
Attacker Value
Unknown

CVE-2024-46872

Disclosure Date: October 29, 2024 (last updated November 09, 2024)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks
Attacker Value
Unknown

CVE-2024-50052

Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.
0
Attacker Value
Unknown

CVE-2024-10241

Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
0
Attacker Value
Unknown

CVE-2024-10214

Disclosure Date: October 28, 2024 (last updated November 06, 2024)
Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.
Attacker Value
Unknown

CVE-2024-9155

Disclosure Date: September 26, 2024 (last updated September 27, 2024)
Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have not been linked to a post which allows an attacker to view them in channels that they are a member of.
0
Attacker Value
Unknown

CVE-2024-47145

Disclosure Date: September 26, 2024 (last updated September 27, 2024)
Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.
Attacker Value
Unknown

CVE-2024-47003

Disclosure Date: September 26, 2024 (last updated September 27, 2024)
Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker to send a non-string value as the message of a permalink post and crash the frontend.