Show filters
381 Total Results
Displaying 51-60 of 381
Sort by:
Attacker Value
Unknown
CVE-2024-39839
Disclosure Date: August 01, 2024 (last updated September 05, 2024)
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadn't been synced before.
0
Attacker Value
Unknown
CVE-2024-39837
Disclosure Date: August 01, 2024 (last updated September 05, 2024)
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.
0
Attacker Value
Unknown
CVE-2024-39832
Disclosure Date: August 01, 2024 (last updated August 24, 2024)
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled.
0
Attacker Value
Unknown
CVE-2024-39777
Disclosure Date: August 01, 2024 (last updated August 24, 2024)
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local channel, and that local channel will then become shared without the consent of the local admin.
0
Attacker Value
Unknown
CVE-2024-39274
Disclosure Date: August 01, 2024 (last updated August 24, 2024)
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the sync message is a shared channel, when shared channels are enabled, which allows a malicious remote to add users to arbitrary teams and channels
0
Attacker Value
Unknown
CVE-2024-36492
Disclosure Date: August 01, 2024 (last updated August 24, 2024)
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing users in shared channels. which allows a malicious remote to overwrite an existing local user.
0
Attacker Value
Unknown
CVE-2024-29977
Disclosure Date: August 01, 2024 (last updated August 24, 2024)
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts
0
Attacker Value
Unknown
CVE-2024-39767
Disclosure Date: July 15, 2024 (last updated July 17, 2024)
Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.
0
Attacker Value
Unknown
CVE-2024-32945
Disclosure Date: July 15, 2024 (last updated July 17, 2024)
Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
0
Attacker Value
Unknown
CVE-2024-6428
Disclosure Date: July 03, 2024 (last updated July 06, 2024)
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause some broken functionality in User Management such administrative actions against the user not working.
0