Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2022-2408
Disclosure Date: July 14, 2022 (last updated February 24, 2025)
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.
0
Attacker Value
Unknown
CVE-2022-2406
Disclosure Date: July 14, 2022 (last updated February 24, 2025)
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.
0
Attacker Value
Unknown
CVE-2022-2401
Disclosure Date: July 14, 2022 (last updated February 24, 2025)
Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.
0
Attacker Value
Unknown
CVE-2022-1982
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.
0