Show filters
685 Total Results
Displaying 41-50 of 685
Sort by:
Attacker Value
Unknown

CVE-2024-36250

Disclosure Date: November 09, 2024 (last updated November 15, 2024)
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
Attacker Value
Unknown

CVE-2024-3935

Disclosure Date: October 30, 2024 (last updated January 30, 2025)
In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur with a subsequent crash of the broker.
Attacker Value
Unknown

CVE-2024-10525

Disclosure Date: October 30, 2024 (last updated January 30, 2025)
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.
Attacker Value
Unknown

CVE-2024-47401

Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn could cause the application to crash by sending a specially crafted request to Playbooks.
0
Attacker Value
Unknown

CVE-2024-46872

Disclosure Date: October 29, 2024 (last updated November 09, 2024)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks
Attacker Value
Unknown

CVE-2024-50052

Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.
0
Attacker Value
Unknown

CVE-2024-10241

Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
0
Attacker Value
Unknown

CVE-2024-10214

Disclosure Date: October 28, 2024 (last updated November 06, 2024)
Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.
Attacker Value
Unknown

CVE-2024-49628

Disclosure Date: October 20, 2024 (last updated October 23, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in WhileTrue Most And Least Read Posts Widget allows Cross Site Request Forgery.This issue affects Most And Least Read Posts Widget: from n/a through 2.5.18.
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.