cbcvebase.

Mattermost Server vulnerabilities

417 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
417
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH77MEDIUM288LOW36

Vulnerabilities

Page 11 of 21
CVE-2024-4198LOWCVSS 2.7≥ 8.1.0, < 8.1.12≥ 9.5.0, < 9.5.3+1 more2024-04-26
CVE-2024-4198 [LOW] CWE-284 CVE-2024-4198: Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role c Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.
nvd
CVE-2024-2447MEDIUMCVSS 6.5≥ 8.1.0, < 8.1.11≥ 9.3.0, < 9.3.3+2 more2024-04-05
CVE-2024-2447 [MEDIUM] CWE-284 CVE-2024-2447: Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9. Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.
nvd
CVE-2024-28949MEDIUMCVSS 6.5≥ 8.1.0, < 8.1.11≥ 9.3.0, < 9.3.3+2 more2024-04-05
CVE-2024-28949 [MEDIUM] CWE-400 CVE-2024-28949: Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.
nvd
CVE-2024-21848LOWCVSS 3.1≥ 8.1.0, < 8.1.112024-04-05
CVE-2024-21848 [LOW] CWE-284 CVE-2024-21848: Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel
nvd
CVE-2024-29221LOWCVSS 3.8≥ 8.1.0, < 8.1.11≥ 9.3.0, < 9.3.3+2 more2024-04-05
CVE-2024-29221 [LOW] CWE-284 CVE-2024-29221: Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the invite ID of their team, thus allowing them to invite users, even if the "Add Members" permission was explicitly remov
nvd
CVE-2024-2450HIGHCVSS 8.8≥ 8.1.0, < 8.1.10≥ 9.2.0, < 9.2.6+3 more2024-03-15
CVE-2024-2450 [HIGH] CWE-287 CVE-2024-2450: Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9. Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email to SAML authentication, allowing an authenticated attacker to take over other user accounts via a crafted switch request under specific conditions.
nvd
CVE-2024-28053MEDIUMCVSS 6.5≥ 8.1.0, < 8.1.102024-03-15
CVE-2024-28053 [MEDIUM] CWE-400 CVE-2024-28053: Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.
nvd
CVE-2024-2445MEDIUMCVSS 6.1≥ 8.1.0, < 8.1.10≥ 9.2.0, < 9.2.6+2 more2024-03-15
CVE-2024-2445 [MEDIUM] CWE-74 CVE-2024-2445: Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9 Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to escape user-controlled outputs when generating HTML pages, which allows an attacker to perform reflected cross-site scripting attacks against the users of the Mattermost server.
nvd
CVE-2024-2446MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.10≥ 9.2.0, < 9.2.6+2 more2024-03-15
CVE-2024-2446 [MEDIUM] CWE-400 CVE-2024-2446: Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9. Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit the number of @-mentions processed per message, allowing an authenticated attacker to crash the client applications of other users via large, crafted messages.
nvd
CVE-2024-1952MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.92024-02-29
CVE-2024-1952 [MEDIUM] CWE-200 CVE-2024-1952: Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugi Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member of.
nvd
CVE-2024-1887MEDIUMCVSS 4.3fixed in 8.1.9≥ 9.2.0, < 9.2.5+1 more2024-02-29
CVE-2024-1887 [MEDIUM] CWE-284 CVE-2024-1887: Mattermost fails to check if compliance export is enabled when fetching posts of public channels all Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is not a member of the public channel to fetch the posts, which will not be audited in the compliance export.
nvd
CVE-2024-23493MEDIUMCVSS 6.5fixed in 8.1.9≥ 9.0.0, < 9.2.5+2 more2024-02-29
CVE-2024-23493 [MEDIUM] CWE-200 CVE-2024-23493: Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowin Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of.
nvd
CVE-2024-1888MEDIUMCVSS 4.3fixed in 8.1.9≥ 9.2.0, < 9.2.5+2 more2024-02-29
CVE-2024-1888 [MEDIUM] CWE-284 CVE-2024-1888: Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a tea Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server
nvd
CVE-2024-23488MEDIUMCVSS 4.3fixed in 8.1.9≥ 9.0.0, < 9.4.22024-02-29
CVE-2024-23488 [MEDIUM] CWE-284 CVE-2024-23488: Mattermost fails to properly restrict the access of files attached to posts in an archived channel, Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members being able to access files of archived channels even if the “Allow users to view archived channels” option is disabled.
nvd
CVE-2024-1953MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.9≥ 9.2.0, < 9.2.5+2 more2024-02-29
CVE-2024-1953 [MEDIUM] CWE-400 CVE-2024-1953: Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to li Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, allowing an authenticated attacker to cause the server to run out of memory and crash by issuing an unusually large HTTP request.
nvd
CVE-2024-1942MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.9≥ 9.2.0, < 9.2.5+1 more2024-02-29
CVE-2024-1942 [MEDIUM] CWE-284 CVE-2024-1942: Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an authenticated attacker to access the contents of individual posts in channels they are not a member of.
nvd
CVE-2024-24988MEDIUMCVSS 6.5fixed in 8.1.8≥ 9.0.0, < 9.1.5+1 more2024-02-29
CVE-2024-24988 [MEDIUM] CWE-400 CVE-2024-24988: Mattermost fails to properly validate the length of the emoji value in the custom user status, allow Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
nvd
CVE-2024-1949LOWCVSS 2.6≥ 8.1.0, < 8.1.9≥ 9.4.0, < 9.4.22024-02-29
CVE-2024-1949 [LOW] CWE-200 CVE-2024-1949: A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authent A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts.
nvd
CVE-2024-1402MEDIUMCVSS 4.3≤ 8.1.7≥ 9.0.0, ≤ 9.1.4+1 more2024-02-09
CVE-2024-1402 [MEDIUM] CWE-400 CVE-2024-1402: Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit t Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post and to crash the server due to overloading when clients attemp
nvd
CVE-2024-24774MEDIUMCVSS 4.1≤ 8.1.72024-02-09
CVE-2024-24774 [MEDIUM] CWE-863 CVE-2024-24774: Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the subscription resulting in registered users on Jira being able to create webhooks that give them access to all Jira issues.
nvd
Mattermost Server vulnerabilities | cvebase