Show filters
897 Total Results
Displaying 311-320 of 897
Sort by:
Attacker Value
Unknown

CVE-2023-5330

Disclosure Date: October 09, 2023 (last updated February 25, 2025)
Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.
Attacker Value
Unknown

CVE-2023-5160

Disclosure Date: October 02, 2023 (last updated February 25, 2025)
Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled
Attacker Value
Unknown

CVE-2023-5196

Disclosure Date: September 29, 2023 (last updated February 25, 2025)
Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.
Attacker Value
Unknown

CVE-2023-5195

Disclosure Date: September 29, 2023 (last updated February 25, 2025)
Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of
Attacker Value
Unknown

CVE-2023-5194

Disclosure Date: September 29, 2023 (last updated February 25, 2025)
Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager
Attacker Value
Unknown

CVE-2023-5193

Disclosure Date: September 29, 2023 (last updated February 25, 2025)
Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.
Attacker Value
Unknown

CVE-2023-5159

Disclosure Date: September 29, 2023 (last updated February 25, 2025)
Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user edit permissions to manage/update bots.
Attacker Value
Unknown

CVE-2023-41109

Disclosure Date: August 28, 2023 (last updated February 25, 2025)
SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.
Attacker Value
Unknown

CVE-2023-4478

Disclosure Date: August 25, 2023 (last updated February 25, 2025)
Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.
Attacker Value
Unknown

CVE-2020-28840

Disclosure Date: August 11, 2023 (last updated February 25, 2025)
Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).