📦 Mattermost

by Mattermost

🔍 What is Mattermost?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-39777

HIGH CVSS 8.7 Aug 1, 2024

This vulnerability in Mattermost allows remote attackers to forcibly share local channels without administrator consent when shared channels are enabled. Attackers can send unsolicited invites with ex...

CVE-2024-36492

HIGH CVSS 7.4 Aug 1, 2024

This vulnerability in Mattermost allows a malicious remote user in a shared channel to overwrite an existing local user's account. This affects Mattermost servers running vulnerable versions with shar...

CVE-2024-39830

HIGH CVSS 8.1 Jul 3, 2024

Mattermost versions with shared channels enabled are vulnerable to a timing attack that allows retrieval of remote cluster tokens. Attackers can exploit this by measuring response time differences dur...

CVE-2023-7114

HIGH CVSS 7.1 Dec 29, 2023

Mattermost versions 2.10.0 and earlier contain a CSRF vulnerability due to improper sanitization of deeplink paths. This allows attackers to trick authenticated users into performing unintended action...

CVE-2023-3615

HIGH CVSS 8.1 Jul 17, 2023

The Mattermost iOS app fails to properly validate TLS server certificates during WebSocket connection initialization, allowing network attackers to perform man-in-the-middle attacks and intercept comm...

CVE-2024-42411

MEDIUM CVSS 5.3 Aug 22, 2024

This vulnerability in Mattermost allows authenticated users to manipulate the creation date of their accounts via the POST /api/v4/users endpoint, tricking administrators into believing accounts are o...

CVE-2024-8071

MEDIUM CVSS 4.7 Aug 22, 2024

This vulnerability allows users with edit access to the permissions section of the Mattermost system console to escalate their privileges to System Admin by adding the 'manage_system' permission to th...

CVE-2024-32939

MEDIUM CVSS 4.3 Aug 22, 2024

This vulnerability in Mattermost exposes remote users' email addresses when shared channels are enabled, even when email visibility is otherwise restricted. It affects organizations using Mattermost w...

CVE-2024-39836

MEDIUM CVSS 4.8 Aug 22, 2024

This vulnerability allows remote/synthetic users created through shared channels to receive email notifications and reset passwords using munged email addresses. It affects Mattermost instances runnin...