Show filters
685 Total Results
Displaying 41-50 of 685
Sort by:
Attacker Value
Unknown
CVE-2024-36250
Disclosure Date: November 09, 2024 (last updated November 15, 2024)
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
0
Attacker Value
Unknown
CVE-2024-3935
Disclosure Date: October 30, 2024 (last updated January 30, 2025)
In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur with a subsequent crash of the broker.
0
Attacker Value
Unknown
CVE-2024-10525
Disclosure Date: October 30, 2024 (last updated January 30, 2025)
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.
0
Attacker Value
Unknown
CVE-2024-47401
Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn could cause the application to crash by sending a specially crafted request to Playbooks.
0
Attacker Value
Unknown
CVE-2024-46872
Disclosure Date: October 29, 2024 (last updated November 09, 2024)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks
0
Attacker Value
Unknown
CVE-2024-50052
Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.
0
Attacker Value
Unknown
CVE-2024-10241
Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
0
Attacker Value
Unknown
CVE-2024-10214
Disclosure Date: October 28, 2024 (last updated November 06, 2024)
Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.
0
Attacker Value
Unknown
CVE-2024-49628
Disclosure Date: October 20, 2024 (last updated October 23, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in WhileTrue Most And Least Read Posts Widget allows Cross Site Request Forgery.This issue affects Most And Least Read Posts Widget: from n/a through 2.5.18.
0
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0