CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2017-18899

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2017-18887

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.

    Published: 19 Jun 2020
    9.8
    Critical

    CVE-2017-18888

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2017-18893

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.

    Published: 19 Jun 2020
    8.1
    High

    CVE-2017-18894

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2017-18896

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2017-18897

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.

    Published: 19 Jun 2020
    9.8
    Critical

    CVE-2017-18885

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2017-18901

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team invite ID by requesting a JSON document.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2017-18889

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could create fictive system-message posts via webhooks and slash commands, in the v3 or v4 REST API.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2017-18890

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker to create a button that, when pressed by a user, launches an API request.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2017-18892

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2017-18891

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.

    Published: 19 Jun 2020
    8.1
    High

    CVE-2017-18884

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.

    Published: 19 Jun 2020
    9.1
    Critical

    CVE-2017-18883

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2017-18882

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2017-18881

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2017-18879

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the author_link field of a Slack attachment.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2017-18878

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.

    Published: 19 Jun 2020
    6.5
    Medium

    CVE-2017-18874

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2017-18873

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) via a misformatted post.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2017-18872

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2018-21252

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail addresses to bypass a domain-based policy for signups.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2018-21256

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for group-message channel creation) via the Group message slash command.

    Published: 19 Jun 2020
    8.8
    High

    CVE-2018-21264

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response.

    Published: 19 Jun 2020
    3.3
    Low

    CVE-2020-3972

    Last Modified: 21 Nov 2024

    VMware Tools for macOS (11.x.x and prior before 11.1.1) contains a denial-of-service vulnerability in the Host-Guest File System (HGFS) implementation. Successful exploitation of this issue may allow attackers with non-admin privileges on guest macOS virtual machines to create a denial-of-service condition on their own VMs.

    Published: 19 Jun 2020
    6.3
    Medium

    CVE-2020-13277

    Last Modified: 21 Nov 2024

    An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5

    Published: 19 Jun 2020
    5.4
    Medium

    CVE-2020-14926

    Last Modified: 21 Nov 2024

    CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.

    Published: 19 Jun 2020
    4.8
    Medium

    CVE-2020-14927

    Last Modified: 21 Nov 2024

    Navigate CMS 2.9 allows XSS via the Alias or Real URL field of the "Web Sites > Create > Aliases > Add" screen.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2018-21257

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2018-21261

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the team invite_id, which leads to unintended excessive invitation privileges.

    Published: 19 Jun 2020
    7.5
    High

    CVE-2018-21262

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX text.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2018-21265

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).

    Published: 19 Jun 2020
    7.5
    High

    CVE-2017-18871

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denial of service (application crash) via an @ character before a JavaScript field name.

    Published: 19 Jun 2020
    6.5
    Medium

    CVE-2018-21250

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a denial of service (memory consumption) via crafted image dimensions.

    Published: 19 Jun 2020
    6.1
    Medium

    CVE-2017-18877

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page.

    Published: 19 Jun 2020
    4.9
    Medium

    CVE-2017-18876

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2018-21255

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to modify that channel.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2018-21254

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command.

    Published: 19 Jun 2020
    2.7
    Low

    CVE-2018-21260

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent during certain user-management operations, violating user privacy.

    Published: 19 Jun 2020
    9.8
    Critical

    CVE-2018-21251

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.

    Published: 19 Jun 2020
    3.7
    Low

    CVE-2018-21249

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 5.3.0. It mishandles timing.

    Published: 19 Jun 2020
    4.9
    Medium

    CVE-2017-18875

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can create arbitrary files.

    Published: 19 Jun 2020
    4.3
    Medium

    CVE-2017-18870

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2018-21259

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel.

    Published: 19 Jun 2020
    5.3
    Medium

    CVE-2019-20889

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation.

    Published: 19 Jun 2020
    7.5
    High

    CVE-2018-21248

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials.

    Published: 19 Jun 2020
    7.5
    High

    CVE-2019-20888

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumption) via an outgoing webhook or a slash command integration.

    Published: 19 Jun 2020
    7.5
    High

    CVE-2019-20886

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.

    Published: 19 Jun 2020
    8.8
    High

    CVE-2018-21263

    Last Modified: 21 Nov 2024

    An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response.

    Published: 19 Jun 2020