Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2024-45835

Disclosure Date: September 16, 2024 (last updated November 02, 2024)
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
Attacker Value
Unknown

CVE-2024-39772

Disclosure Date: September 16, 2024 (last updated November 02, 2024)
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
Attacker Value
Unknown

CVE-2024-39613

Disclosure Date: September 16, 2024 (last updated September 21, 2024)
Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.
Attacker Value
Unknown

CVE-2024-37182

Disclosure Date: June 14, 2024 (last updated August 08, 2024)
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
Attacker Value
Unknown

CVE-2024-36287

Disclosure Date: June 14, 2024 (last updated August 08, 2024)
Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.
Attacker Value
Unknown

CVE-2023-5920

Disclosure Date: November 02, 2023 (last updated November 10, 2023)
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.
Attacker Value
Unknown

CVE-2023-5876

Disclosure Date: November 02, 2023 (last updated November 10, 2023)
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
Attacker Value
Unknown

CVE-2023-5875

Disclosure Date: November 02, 2023 (last updated November 10, 2023)
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server
Attacker Value
Unknown

CVE-2023-5339

Disclosure Date: October 17, 2023 (last updated October 25, 2023)
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. 
Attacker Value
Unknown

CVE-2023-2000

Disclosure Date: May 02, 2023 (last updated October 08, 2023)
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website