CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2016-11084

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2016-11083

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2016-11082

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2016-11081

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web browser.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2016-11080

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view account details.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2016-11079

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.

    Published: 19 Jun 2020
    6.5
    Medium

    CVE-2016-11078

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI.

    Published: 19 Jun 2020
    2.7
    Low

    CVE-2016-11077

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change the account name and e-mail address of an LDAP account.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2016-11076

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2016-11075

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API.

    Published: 19 Jun 2020
    9.8
    Critical

    CVE-2016-11074

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2016-11073

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.

    Published: 19 Jun 2020
    6.5
    Medium

    CVE-2016-11072

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2016-11071

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.

    Published: 19 Jun 2020
    5.4
    Medium

    CVE-2016-11070

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.

    Published: 19 Jun 2020
    7.5
    High

    CVE-2016-11069

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2016-11068

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2016-11067

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.

    Published: 19 Jun 2020
    7.5
    High

    CVE-2016-11066

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2016-11065

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance.

    Published: 19 Jun 2020
    9.8
    Critical

    CVE-2016-11064

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2016-11063

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2016-11062

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2017-18921

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page.

    Published: 19 Jun 2020
    9.8
    Critical

    CVE-2017-18920

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2017-18919

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation.

    Published: 19 Jun 2020
    4.9
    Medium

    CVE-2017-18918

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate at an arbitrary pathname.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2017-18907

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2017-18916

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission restriction.

    Published: 19 Jun 2020
    7.5
    High

    CVE-2017-18917

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens.

    Published: 19 Jun 2020
    8.1
    High

    CVE-2017-18906

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody else's account.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2017-18905

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2017-18913

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.

    Published: 19 Jun 2020
    9.8
    Critical

    CVE-2017-18908

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-mail address.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2017-18914

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allowlist.

    Published: 19 Jun 2020
    9.8
    Critical

    CVE-2017-18915

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoint access.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2020-9495

    Last Modified: 21 Nov 2024

    Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP server by providing special values to the login form. With certain characters it is possible to modify the LDAP filter used to query the LDAP users. By measuring the response time for the login request, arbitrary attribute data can be retrieved from LDAP user objects.

    Published: 19 Jun 2020
    7.5
    High

    CVE-2020-14929

    Last Modified: 21 Nov 2024

    Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.

    Published: 19 Jun 2020
    7.5
    High

    CVE-2017-18909

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2017-18910

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links.

    Published: 19 Jun 2020
    9.1
    Critical

    CVE-2017-18911

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.

    Published: 19 Jun 2020
    9.8
    Critical

    CVE-2017-18912

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2017-18904

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file.

    Published: 19 Jun 2020
    8.8
    High

    CVE-2017-18903

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2017-18902

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2017-18898

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially cause a web browser to hang.

    Published: 19 Jun 2020
    9.8
    Critical

    CVE-2017-18900

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.

    Published: 19 Jun 2020
    8.8
    High

    CVE-2017-18886

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2017-18895

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive information (user statuses) via a REST API version 4 endpoint.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2017-18880

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of a Slack attachment.

    Published: 19 Jun 2020