Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-8pff-p3gx-w4jf
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server vulnerable to XSS via an uploaded file

    Published
    24 May 2022
    GHSA-g24c-fx4v-xg9w
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server has Insufficient Session Expiration when used as an OAuth 2.0 service provider

    Published
    24 May 2022
    GHSA-fpcr-4rr5-hpcp
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used

    Published
    24 May 2022
    GHSA-34cx-hvm4-vx7j
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server password reset email requests can be sent to attacker-provided email addresses

    Published
    24 May 2022
    GHSA-42x9-rr3c-gr59
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server vulnerable to XSS through channel headers

    Published
    24 May 2022
    GHSA-8q4v-35v6-g8wr
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable CSV Injection

    Published
    24 May 2022
    GHSA-c253-8hr4-r8v9
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server exposes private team invite ID

    Published
    24 May 2022
    GHSA-fcwg-45jh-5qhf
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server vulnerable to CSRF if CORS is enabled

    Published
    24 May 2022
    GHSA-r6j5-fqx9-7qv9
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server SAML implementation does not require encryption or signature verification as default

    Published
    24 May 2022
    GHSA-wj5w-qghh-gvqp
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server does not neutralize HTML content in an Email template field

    Published
    24 May 2022
    GHSA-m497-hq5x-6jcv
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server allows attackers to create buttons that can launch API requests

    Published
    24 May 2022
    GHSA-v2vm-hq26-5jv6
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to SQL Injection when executing multiple POST requests

    Published
    24 May 2022
    GHSA-63wg-qmrv-7q66
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server allows attackers to log sensitive information via DEBUG REST API logging endpoint

    Published
    24 May 2022
    GHSA-f7c3-7vp3-44p6
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server mishandles redirect denial action

    Published
    24 May 2022
    GHSA-vrh2-rprg-rgc6
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server does not safeguard against phishing via error page links

    Published
    24 May 2022
    GHSA-887v-xh2x-47cm
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to XSS through display name field

    Published
    24 May 2022
    GHSA-9589-mq83-f749
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to DoS through maliciously crafted posts

    Published
    24 May 2022
    GHSA-gg42-mwr6-p82c
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server has intermittent Authorization bypass for resource-owners

    Published
    24 May 2022
    GHSA-h742-xx59-r9pq
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server exposes sensitive user status information via REST API version 4 endpoint

    Published
    24 May 2022
    GHSA-wvjg-33p9-938h
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server does not properly restrict use of slash commands

    Published
    24 May 2022
    GHSA-876j-jfqf-m7j7
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server exposes OAuth personal access tokens to attackers

    Published
    24 May 2022
    GHSA-jp57-4x34-5v94
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to webhook and slash command manipulation

    Published
    24 May 2022
    GHSA-g78f-6xq7-rrhq
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials

    Published
    24 May 2022
    GHSA-9rr5-q43r-ccv4
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server does not prevent System Admin from arbitrary file creation

    Published
    24 May 2022
    GHSA-498j-wxww-j897
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to XSS through author_link field in Slack attachments

    Published
    24 May 2022
    GHSA-h564-6gc2-fcc6
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server allows users with a session ID to revoke another users' session

    Published
    24 May 2022
    GHSA-w8cc-3h7q-jhc3
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server has low entropy for authorization data as an OAuth 2.0 Service Provider

    Published
    24 May 2022
    GHSA-x6mw-hf2j-vqpc
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to channel invisibility DoS via misformatted post

    Published
    24 May 2022
    GHSA-35c4-5qfp-wxj6
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server exposes team creator's e-mail address to other members

    Published
    24 May 2022
    GHSA-9x8x-w6g5-hx4w
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to XSS attacks against an OAuth 2.0 allow/deny page

    Published
    24 May 2022
    GHSA-hjqh-j6rj-gh8q
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to Path Traversal when files are stored locally

    Published
    24 May 2022
    GHSA-2j9c-76pp-xc5q
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server allows XSS via redirect URL

    Published
    24 May 2022
    GHSA-m78r-2x6w-qqjp
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to XSS through crafted links

    Published
    24 May 2022
    GHSA-rm24-25xm-9454
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution

    Published
    24 May 2022
    GHSA-vw57-55f8-c73q
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server allows XSS via CSRF

    Published
    24 May 2022
    GHSA-hgrp-fgm8-56g8
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server's OAuth 2.0 service is vulnerable to attack through Missing Authorization

    Published
    24 May 2022
    GHSA-8qg8-c7mw-6fj7
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to Directory Traversal by System Admins

    Published
    24 May 2022
    GHSA-jc6w-8r7f-vmp5
    Fix available
    Packages

    github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server

    Summary

    Mattermost Server vulnerable to Denial of Service through `@` character prefix inserted into JavaScript field names

    Published
    24 May 2022
    GHSA-5q37-9874-qxcw
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server exposes information stored by a web browser

    Published
    24 May 2022
    GHSA-g3f3-p9rc-775p
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server exposes account details to any Team Administrator

    Published
    24 May 2022
    GHSA-mj8v-773w-5qhj
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server allows System Admin to modify LDAP account names and email addresses

    Published
    24 May 2022
    GHSA-ffcc-qr2v-3qmv
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to Uncontrolled Resource Consumption

    Published
    24 May 2022
    GHSA-r93j-3mmp-px57
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server: initial_load API exposes unnecessary information

    Published
    24 May 2022
    GHSA-qrf6-h5fc-7m96
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server does not enforce rate limits on password change attempts

    Published
    24 May 2022
    GHSA-43m6-wvc8-2m7j
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server's Session ID and Session Token are potentially compromised

    Published
    24 May 2022
    GHSA-9jrx-fgrm-96qh
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to XSS via a Legal or Support setting

    Published
    24 May 2022
    GHSA-j26g-95ph-2mwv
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server: Insufficient Password-Reset Link Invalidation

    Published
    24 May 2022
    GHSA-q3g9-hgrx-hwhx
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server exposes sensitive information about team URLs via an API

    Published
    24 May 2022
    GHSA-379p-37xc-q963
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server does not check if cookies are used over SSL

    Published
    24 May 2022
    GHSA-7vmw-6c7h-rrrv
    Fix available
    Packages

    github.com/mattermost/mattermost-server

    Summary

    Mattermost Server is vulnerable to Code Injection through its LDAP fields

    Published
    24 May 2022