Mattermost Server vulnerabilities
417 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
417
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH77MEDIUM288LOW36
Vulnerabilities
Page 15 of 21
CVE-2018-21251CRITICALCVSS 9.8fixed in 5.1.1v5.2.02020-06-19
CVE-2018-21251 [CRITICAL] CWE-862 CVE-2018-21251: An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed i
An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.
nvd
CVE-2017-18912CRITICALCVSS 9.8fixed in 3.6.7≥ 3.7.0, < 3.7.5+1 more2020-06-19
CVE-2017-18912 [CRITICAL] CWE-22 CVE-2017-18912: An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker t
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file.
nvd
CVE-2017-18888CRITICALCVSS 9.8fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18888 [CRITICAL] CWE-89 CVE-2017-18888: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.
nvd
CVE-2016-11074CRITICALCVSS 9.8fixed in 3.0.02020-06-19
CVE-2016-11074 [CRITICAL] CWE-287 CVE-2016-11074: An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
nvd
CVE-2017-18908CRITICALCVSS 9.8fixed in 3.9.2≥ 3.10.0, < 3.10.22020-06-19
CVE-2017-18908 [CRITICAL] CWE-287 CVE-2017-18908: An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset reque
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-mail address.
nvd
CVE-2017-18920CRITICALCVSS 9.8fixed in 3.6.22020-06-19
CVE-2017-18920 [CRITICAL] CVE-2017-18920: An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the
An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy.
nvd
CVE-2019-20888HIGHCVSS 7.5fixed in 4.10.5≥ 5.5.0, < 5.5.2+2 more2020-06-19
CVE-2019-20888 [HIGH] CWE-401 CVE-2019-20888: An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attacke
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumption) via an outgoing webhook or a slash command integration.
nvd
CVE-2020-14450HIGHCVSS 7.5fixed in 5.22.02020-06-19
CVE-2020-14450 [HIGH] CVE-2020-14450: An issue was discovered in Mattermost Server before 5.22.0. The markdown renderer allows attackers t
An issue was discovered in Mattermost Server before 5.22.0. The markdown renderer allows attackers to cause a denial of service (client-side), aka MMSA-2020-0017.
nvd
CVE-2018-21248HIGHCVSS 7.5fixed in 5.4.02020-06-19
CVE-2018-21248 [HIGH] CWE-522 CVE-2018-21248: An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous a
An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials.
nvd
CVE-2020-14458HIGHCVSS 7.5fixed in 5.19.02020-06-19
CVE-2020-14458 [HIGH] CVE-2020-14458: An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels
An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel by name" API, aka MMSA-2020-0004.
nvd
CVE-2020-14453HIGHCVSS 7.5fixed in 5.21.02020-06-19
CVE-2020-14453 [HIGH] CWE-345 CVE-2020-14453: An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropria
An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, which allows attackers to cause a denial of service, aka MMSA-2020-0005.
nvd
CVE-2017-18871HIGHCVSS 7.5fixed in 4.2.2≥ 4.3.0, < 4.3.4+2 more2020-06-19
CVE-2017-18871 [HIGH] CVE-2017-18871: An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attack
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denial of service (application crash) via an @ character before a JavaScript field name.
nvd
CVE-2020-14448HIGHCVSS 7.5fixed in 5.23.02020-06-19
CVE-2020-14448 [HIGH] CWE-835 CVE-2020-14448: An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies allow a
An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0020.
nvd
CVE-2019-20845HIGHCVSS 7.5fixed in 5.18.02020-06-19
CVE-2019-20845 [HIGH] CWE-770 CVE-2019-20845: An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of
An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory consumption) via a large Slack import.
nvd
CVE-2017-18909HIGHCVSS 7.5fixed in 3.9.02020-06-19
CVE-2017-18909 [HIGH] CWE-295 CVE-2017-18909: An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signatur
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
nvd
CVE-2019-20858HIGHCVSS 7.5fixed in 5.15.02020-06-19
CVE-2019-20858 [HIGH] CWE-400 CVE-2019-20858: An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of
An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consumption) via crafted characters in a SQL LIKE clause to an APIv4 endpoint.
nvd
CVE-2017-18906HIGHCVSS 8.1fixed in 3.9.2≥ 3.10.0, < 3.10.22020-06-19
CVE-2017-18906 [HIGH] CWE-287 CVE-2017-18906: An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OA
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody else's account.
nvd
CVE-2017-18886HIGHCVSS 8.8fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18886 [HIGH] CWE-732 CVE-2017-18886: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of r
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
nvd
CVE-2019-20854HIGHCVSS 7.5fixed in 5.17.02020-06-19
CVE-2019-20854 [HIGH] CVE-2019-20854: An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a de
An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a denial of service (client-side application crash) via a LaTeX message.
nvd
CVE-2019-20863HIGHCVSS 7.5fixed in 5.13.02020-06-19
CVE-2019-20863 [HIGH] CVE-2019-20863: An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properl
An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted.
nvd