Show filters
412 Total Results
Displaying 21-30 of 412
Sort by:
Attacker Value
Unknown
CVE-2024-54682
Disclosure Date: December 16, 2024 (last updated February 27, 2025)
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin.
0
Attacker Value
Unknown
CVE-2024-54083
Disclosure Date: December 16, 2024 (last updated February 27, 2025)
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a specially crafted post.
0
Attacker Value
Unknown
CVE-2024-48872
Disclosure Date: December 16, 2024 (last updated February 27, 2025)
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which allows an attacker to bypass of "Max failed attempts" restriction and send a big number of login attempts before being blocked via simultaneously sending multiple login requests
0
Attacker Value
Unknown
CVE-2024-12247
Disclosure Date: December 05, 2024 (last updated February 27, 2025)
Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.
0
Attacker Value
Unknown
CVE-2024-11599
Disclosure Date: November 28, 2024 (last updated February 27, 2025)
Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registration.
0
Attacker Value
Unknown
CVE-2024-52032
Disclosure Date: November 09, 2024 (last updated February 27, 2025)
Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to get private channels names of channels that they are not a member of, when Elasticsearch v8 was enabled.
0
Attacker Value
Unknown
CVE-2024-42000
Disclosure Date: November 09, 2024 (last updated February 27, 2025)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels which allows a User or System Manager, with "Read Groups" permission but with no access for channels to retrieve details about private channels that they were not a member of by sending a request to /api/v4/channels.
0
Attacker Value
Unknown
CVE-2024-36250
Disclosure Date: November 09, 2024 (last updated February 27, 2025)
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
0
Attacker Value
Unknown
CVE-2024-47401
Disclosure Date: October 29, 2024 (last updated February 26, 2025)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn could cause the application to crash by sending a specially crafted request to Playbooks.
0
Attacker Value
Unknown
CVE-2024-46872
Disclosure Date: October 29, 2024 (last updated February 26, 2025)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks
0