Filtered by vendor Mattermost
Subscriptions
Total
312 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2019-20879 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 4.3 Medium |
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry. | ||||
CVE-2019-20869 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 5.3 Medium |
An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Update/Patch Channel endpoint for a private channel. | ||||
CVE-2019-20878 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 4.3 Medium |
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled. | ||||
CVE-2019-20875 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 5.3 Medium |
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed. | ||||
CVE-2019-20871 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastrophic backtracking. | ||||
CVE-2019-20864 | 1 Mattermost | 1 Mattermost Plugins | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Plugins before 5.13.0. The GitHub plugin allows an attacker to attach his Mattermost account to a different person's GitHub account. | ||||
CVE-2019-20880 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph. | ||||
CVE-2019-20881 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.3 High |
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA. | ||||
CVE-2019-20889 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 5.3 Medium |
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation. | ||||
CVE-2019-20885 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file. | ||||
CVE-2019-20890 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 4.3 Medium |
An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions. | ||||
CVE-2019-20863 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted. | ||||
CVE-2019-20873 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 6.5 Medium |
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during user activation/deactivation. | ||||
CVE-2019-20876 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 5.4 Medium |
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy. | ||||
CVE-2019-20867 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 5.3 Medium |
An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via one crafted post. | ||||
CVE-2019-20886 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin. | ||||
CVE-2019-20861 | 1 Mattermost | 1 Mattermost Desktop | 2024-08-05 | 8.8 High |
An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link. | ||||
CVE-2019-20884 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 5.3 Medium |
An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post. | ||||
CVE-2019-20857 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 7.5 High |
An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of service (markdown renderer hang) via many backtick characters. | ||||
CVE-2019-20844 | 1 Mattermost | 1 Mattermost Server | 2024-08-05 | 6.5 Medium |
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a direct-message channel by changing the type of a channel. |