Show filters
381 Total Results
Displaying 31-40 of 381
Sort by:
Attacker Value
Unknown

CVE-2024-45843

Disclosure Date: September 26, 2024 (last updated September 27, 2024)
Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.
Attacker Value
Unknown

CVE-2024-42406

Disclosure Date: September 26, 2024 (last updated October 01, 2024)
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files.
Attacker Value
Unknown

CVE-2024-45835

Disclosure Date: September 16, 2024 (last updated November 02, 2024)
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
Attacker Value
Unknown

CVE-2024-39772

Disclosure Date: September 16, 2024 (last updated November 02, 2024)
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
Attacker Value
Unknown

CVE-2024-45833

Disclosure Date: September 16, 2024 (last updated September 24, 2024)
Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the password contains a special character..
Attacker Value
Unknown

CVE-2024-39613

Disclosure Date: September 16, 2024 (last updated September 21, 2024)
Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.
Attacker Value
Unknown

CVE-2024-43105

Disclosure Date: August 23, 2024 (last updated August 23, 2024)
Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.
0
Attacker Value
Unknown

CVE-2024-43780

Disclosure Date: August 22, 2024 (last updated October 17, 2024)
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.
Attacker Value
Unknown

CVE-2024-42497

Disclosure Date: August 22, 2024 (last updated October 17, 2024)
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems manager role with read-only access to teams to perform write operations on teams.
Attacker Value
Unknown

CVE-2024-40884

Disclosure Date: August 22, 2024 (last updated October 18, 2024)
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.