Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2022-2408

Disclosure Date: July 14, 2022 (last updated February 24, 2025)
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.
Attacker Value
Unknown

CVE-2022-2406

Disclosure Date: July 14, 2022 (last updated February 24, 2025)
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.
Attacker Value
Unknown

CVE-2022-2401

Disclosure Date: July 14, 2022 (last updated February 24, 2025)
Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.
Attacker Value
Unknown

CVE-2022-1982

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.