Github.Com Mattermost Mattermost Server V8 vulnerabilities

180 known vulnerabilities affecting github.com/mattermost_mattermost_server_v8.

Total CVEs
180
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH13MEDIUM117LOW43

Vulnerabilities

Page 7 of 9
CVE-2024-10241MEDIUM≥ 0, < 8.0.0-20240813135334-8f3a13122f552024-10-29
CVE-2024-10241 [MEDIUM] CWE-284 Mattermost Server allows user to get private channel names Mattermost Server allows user to get private channel names Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
ghsaosv
CVE-2024-47401MEDIUM≥ 0, < 8.0.0-20240926115259-20ed58906adc2024-10-29
CVE-2024-47401 [MEDIUM] CWE-770 Mattermost Server vulnerable to application crash from attacker-generated large response Mattermost Server vulnerable to application crash from attacker-generated large response Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn could cause the application to cr
ghsaosv
CVE-2024-10214LOW≥ 0, < 8.0.0-20240821220019-0d6b1070a26f2024-10-28
CVE-2024-10214 [LOW] CWE-303 Mattermost incorrectly issues two sessions when using desktop SSO Mattermost incorrectly issues two sessions when using desktop SSO Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 incorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.
ghsaosv
CVE-2024-47003MEDIUM≥ 0, < 8.0.0-20240806094731-69a8b3df0f9f2024-09-26
CVE-2024-47003 [MEDIUM] CWE-400 Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events Mattermost does not strip `embeds` from `metadata` when broadcasting `posted` events. This allows users to include arbitrary embeds in posts, which are then broadcasted via websockets. This can be exploited in many ways, for example to create permalinks with fully customizable content or to trig
ghsaosv
CVE-2024-42497HIGH≥ 9.5.0, < 9.5.8≥ 9.10.0, < 9.10.1+2 more2024-08-22
CVE-2024-42497 [HIGH] CWE-284 Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems manager role with read-only access to teams to perform write operations on teams
ghsaosv
CVE-2024-43780MEDIUM≥ 9.5.0, < 9.5.8≥ 9.10.0, < 9.10.1+2 more2024-08-22
CVE-2024-43780 [MEDIUM] CWE-284 Mattermost allows guest user with read access to upload files to a channel Mattermost allows guest user with read access to upload files to a channel Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.
ghsaosv
CVE-2024-39836MEDIUM≥ 9.9.0, < 9.9.2≥ 9.5.0, < 9.5.8+2 more2024-08-22
CVE-2024-39836 [MEDIUM] CWE-693 Mattermost allows remote/synthetic users to create sessions, reset passwords Mattermost allows remote/synthetic users to create sessions, reset passwords Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when
ghsaosv
CVE-2024-40886MEDIUM≥ 9.9.0, < 9.9.2≥ 9.5.0, < 9.5.8+2 more2024-08-22
CVE-2024-40886 [MEDIUM] CWE-352 Mattermost Cross-Site Request Forgery vulnerability Mattermost Cross-Site Request Forgery vulnerability Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in User Management page of the system console.
ghsaosv
CVE-2024-40884MEDIUM≥ 9.5.0, < 9.5.8≥ 9.10.0, < 9.10.12024-08-22
CVE-2024-40884 [MEDIUM] CWE-284 Mattermost allows team admin user without "Add Team Members" permission to disable invite URL Mattermost allows team admin user without "Add Team Members" permission to disable invite URL Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
ghsaosv
CVE-2024-8071MEDIUM≥ 9.9.0, < 9.9.2≥ 9.5.0, < 9.5.8+2 more2024-08-22
CVE-2024-8071 [MEDIUM] CWE-284 Mattermost doesn't restrict which roles can promote a user as system admin Mattermost doesn't restrict which roles can promote a user as system admin Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to include the `manage_system` permission,
ghsaosv
CVE-2024-32939MEDIUM≥ 9.9.0, < 9.9.2≥ 9.5.0, < 9.5.8+2 more2024-08-22
CVE-2024-32939 [MEDIUM] CWE-284 Mattermost doesn't redact remote users' original email addresses Mattermost doesn't redact remote users' original email addresses Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server.
ghsaosv
CVE-2024-39777CRITICAL≥ 9.9.0, < 9.9.1≥ 9.5.0, < 9.5.7+2 more2024-08-01
CVE-2024-39777 [CRITICAL] CWE-284 Mattermost allows unsolicited invites to expose access to local channels Mattermost allows unsolicited invites to expose access to local channels Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local channel, and that local channel will then b
ghsaosv
CVE-2024-39274CRITICAL≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+2 more2024-08-01
CVE-2024-39274 [CRITICAL] CWE-284 Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the sync message is a shared channel, when shared channels are enabled, which allows a malicious remot
ghsaosv
CVE-2024-41144HIGH≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+3 more2024-08-01
CVE-2024-41144 [HIGH] CWE-284 Mattermost allows remote actor to create/update/delete posts in arbitrary channels Mattermost allows remote actor to create/update/delete posts in arbitrary channels Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled, which allows a malicious remote to create/update/delete arbitrary posts in arbitrary channels
ghsaosv
CVE-2024-29977MEDIUM≥ 9.5.0, < 9.5.7≥ 9.9.0, < 9.9.12024-08-01
CVE-2024-29977 [MEDIUM] CWE-284 Mattermost failed to properly validate synced reactions Mattermost failed to properly validate synced reactions Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts
ghsaosv
CVE-2024-41926MEDIUM≥ 9.5.0, < 9.5.7≥ 9.9.0, < 9.9.1+1 more2024-08-01
CVE-2024-41926 [MEDIUM] CWE-284 Mattermost allows remote actor to set arbitrary RemoteId values for synced users Mattermost allows remote actor to set arbitrary RemoteId values for synced users Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote.
ghsaosv
CVE-2024-39839MEDIUM≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+2 more2024-08-01
CVE-2024-39839 [MEDIUM] CWE-284 Mattermost allows a user on a remote to set their remote username prop to an arbitrary string Mattermost allows a user on a remote to set their remote username prop to an arbitrary string Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be
ghsaosv
CVE-2024-41162MEDIUM≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+3 more2024-08-01
CVE-2024-41162 [MEDIUM] CWE-284 Mattermost allows a remote actor to make an arbitrary local channel read-only Mattermost allows a remote actor to make an arbitrary local channel read-only Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only.
ghsaosv
CVE-2024-36492MEDIUM≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+2 more2024-08-01
CVE-2024-36492 [MEDIUM] CWE-284 Mattermost failed to disallow the modification of local users when syncing users in shared channels Mattermost failed to disallow the modification of local users when syncing users in shared channels Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing users in shared channels. which allows a malicious remote to overwrite an existing local user.
ghsaosv
CVE-2024-39832MEDIUM≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+2 more2024-08-01
CVE-2024-39832 [MEDIUM] CWE-754 Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled.
ghsaosv