Show filters
386 Total Results
Displaying 211-220 of 386
Sort by:
Attacker Value
Unknown
CVE-2022-1337
Disclosure Date: April 13, 2022 (last updated February 23, 2025)
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.
0
Attacker Value
Unknown
CVE-2022-1333
Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorized users to create a specifically drafted Playbook which could trigger a large amount of webhook requests leading to Denial of Service.
0
Attacker Value
Unknown
CVE-2022-1332
Disclosure Date: April 13, 2022 (last updated February 23, 2025)
One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.
0
Attacker Value
Unknown
CVE-2022-1003
Disclosure Date: March 18, 2022 (last updated February 23, 2025)
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
0
Attacker Value
Unknown
CVE-2022-1002
Disclosure Date: March 18, 2022 (last updated February 23, 2025)
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.
0
Attacker Value
Unknown
CVE-2022-0904
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted Apple Pages document.
0
Attacker Value
Unknown
CVE-2022-0903
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.
0
Attacker Value
Unknown
CVE-2022-0708
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.
0
Attacker Value
Unknown
CVE-2021-37867
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, which allows authenticated and unauthorized users to access this information resulting in sensitive & private information disclosure.
0
Attacker Value
Unknown
CVE-2021-37866
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization.
0