Vulnerabilities
Last updated 1 hour ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation | Medium Risk 4.3 | 3 months ago | 2 hours ago |
|
|
Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret | Medium Risk 6.4 | 3 months ago | 2 hours ago |
|
|
Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler | Medium Risk 5.4 | 3 months ago | 2 hours ago |
|
|
Mattermost doesn't validate channel ownership of an existing subscription before applying edits | Medium Risk 6.4 | 3 months ago | 2 hours ago |
|
|
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint | Low Risk 3.8 | 3 months ago | 2 hours ago |
|
|
Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler in github.com/mattermost/mattermost-server | Unknown | 3 hours ago | 2 hours ago |
|
|
Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation in github.com/mattermost/mattermost-server | Unknown | 3 hours ago | 2 hours ago |
|
|
Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret in github.com/mattermost/mattermost-server | Unknown | 3 hours ago | 2 hours ago |
|
|
Mattermost doesn't validate channel ownership of an existing subscription before applying edits in github.com/mattermost/mattermost-server | Unknown | 3 hours ago | 2 hours ago |
|
|
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint in github.com/mattermost/mattermost-server | Unknown | 3 hours ago | 2 hours ago |
|
|
Mattermost has an Incorrect Authorization issue | Low Risk 3.8 | 3 months ago | 6 days ago |
|
|
Mattermost doesn't require system-level permission when patching protected default system roles | Medium Risk 6.7 | 3 months ago | 18 days ago |
|
|
Mattermost Fails to Restrict Certain Operations on System Admins | Medium Risk 4.7 | 1 year ago | 18 days ago |
|
|
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account | Medium Risk 5.3 | 3 months ago | 18 days ago |
|
|
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation | Medium Risk 4.3 | 3 months ago | 18 days ago |
|
|
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel | Medium Risk 4.3 | 3 months ago | 18 days ago |
|
|
Mattermost allows members with permission to convert public channels to private and convert private to public | Medium Risk 5.4 | 1 year ago | 18 days ago |
|
|
Denial of service in Mattermost | Medium Risk 6.5 | 3 years ago | 18 days ago |
|
|
Mattermost notified all users in the channel when using WebSockets to respond individually | Medium Risk 4.3 | 2 years ago | 18 days ago |
|
|
Mattermost viewing archived public channels permissions vulnerability | Medium Risk 4.3 | 2 years ago | 18 days ago |
|
|
Mattermost Open Redirect vulnerability | Medium Risk 4.3 | 2 years ago | 18 days ago |
|
|
Mattermost Improper Access Control vulnerability | Medium Risk 4.3 | 2 years ago | 18 days ago |
|
|
Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability | Medium Risk 4.3 | 2 years ago | 18 days ago |
|
|
Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability | Medium Risk 5.3 | 2 years ago | 18 days ago |
|
|
Mattermost Injection vulnerability | High Risk 7.1 | 2 years ago | 18 days ago |
|
|
Mattermost Uncontrolled Resource Consumption vulnerability | Medium Risk 4.3 | 2 years ago | 18 days ago |
|
|
Mattermost Injection vulnerability | Low Risk 3.1 | 2 years ago | 18 days ago |
|
|
Mattermost Uncontrolled Resource Consumption vulnerability | Medium Risk 5.3 | 2 years ago | 18 days ago |
|
|
Mattermost Improper Access Control vulnerability | Medium Risk 4.3 | 2 years ago | 18 days ago |
|
|
Mattermost Uncontrolled Resource Consumption vulnerability | Medium Risk 4.3 | 2 years ago | 18 days ago |
|
|
Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability | Medium Risk 4.3 | 2 years ago | 18 days ago |
|
|
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints | High Risk 8.8 | 3 months ago | 1 month ago |
|
|
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync | High Risk 7.6 | 3 months ago | 1 month ago |
|
|
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations | Medium Risk 6.5 | 3 months ago | 1 month ago |
|
|
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
|
|
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server | Unknown | 1 month ago | 1 month ago |
Page 1