Filtered by vendor Mattermost
Subscriptions
Filtered by product Mattermost Server
Subscriptions
Total
206 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2018-21252 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 4.3 Medium |
An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail addresses to bypass a domain-based policy for signups. | ||||
CVE-2018-21256 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 4.3 Medium |
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for group-message channel creation) via the Group message slash command. | ||||
CVE-2018-21251 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 9.8 Critical |
An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body. | ||||
CVE-2019-20888 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumption) via an outgoing webhook or a slash command integration. | ||||
CVE-2019-20858 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consumption) via crafted characters in a SQL LIKE clause to an APIv4 endpoint. | ||||
CVE-2019-20887 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 4.3 Medium |
An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts. | ||||
CVE-2019-20868 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated. | ||||
CVE-2019-20874 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during a role change. | ||||
CVE-2019-20879 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 4.3 Medium |
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry. | ||||
CVE-2019-20869 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 5.3 Medium |
An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Update/Patch Channel endpoint for a private channel. | ||||
CVE-2019-20878 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 4.3 Medium |
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled. | ||||
CVE-2019-20875 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 5.3 Medium |
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed. | ||||
CVE-2019-20871 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastrophic backtracking. | ||||
CVE-2019-20880 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph. | ||||
CVE-2019-20881 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.3 High |
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA. | ||||
CVE-2019-20889 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 5.3 Medium |
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation. | ||||
CVE-2019-20885 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file. | ||||
CVE-2019-20890 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 4.3 Medium |
An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions. | ||||
CVE-2019-20863 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted. | ||||
CVE-2019-20873 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 6.5 Medium |
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during user activation/deactivation. |