cbcvebase.

Mattermost Server vulnerabilities

417 known vulnerabilities affecting mattermost/mattermost_server.

Total CVEs
417
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH77MEDIUM288LOW36

Vulnerabilities

Page 16 of 21
CVE-2019-20868HIGHCVSS 7.5fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20868 [HIGH] CWE-20 CVE-2019-20868: An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated. An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.
nvd
CVE-2017-18917HIGHCVSS 7.5≥ 3.6.0, < 3.6.7≥ 3.7.0, < 3.7.5+1 more2020-06-19
CVE-2017-18917 [HIGH] CWE-916 CVE-2017-18917: An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used f An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens.
nvd
CVE-2019-20880HIGHCVSS 7.5fixed in 4.10.7≥ 5.6.0, < 5.6.5+2 more2020-06-19
CVE-2019-20880 [HIGH] CWE-770 CVE-2019-20880: An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attac An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph.
nvd
CVE-2019-20859HIGHCVSS 7.5fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20859 [HIGH] CVE-2019-20859: An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input.
nvd
CVE-2019-20874HIGHCVSS 7.5fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20874 [HIGH] CVE-2019-20874: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attac An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during a role change.
nvd
CVE-2019-20862HIGHCVSS 7.5fixed in 5.13.02020-06-19
CVE-2019-20862 [HIGH] CVE-2019-20862: An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash com An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands.
nvd
CVE-2019-20857HIGHCVSS 7.5fixed in 5.16.02020-06-19
CVE-2019-20857 [HIGH] CVE-2019-20857: An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of service (markdown renderer hang) via many backtick characters.
nvd
CVE-2018-21263HIGHCVSS 8.8fixed in 4.5.2≥ 4.6.0, < 4.6.2+1 more2020-06-19
CVE-2018-21263 [HIGH] CWE-287 CVE-2018-21263: An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authe An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response.
nvd
CVE-2019-20841HIGHCVSS 8.8fixed in 5.9.7≥ 5.15.0, < 5.15.4+3 more2020-06-19
CVE-2019-20841 [HIGH] CWE-352 CVE-2019-20841: An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks.
nvd
CVE-2019-20881HIGHCVSS 7.3fixed in 5.8.02020-06-19
CVE-2019-20881 [HIGH] CWE-307 CVE-2019-20881: An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
nvd
CVE-2018-21258HIGHCVSS 7.5fixed in 5.1.02020-06-19
CVE-2018-21258 [HIGH] CWE-74 CVE-2018-21258: An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of se An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.
nvd
CVE-2019-20871HIGHCVSS 7.5fixed in 4.10.8≥ 5.7.0, < 5.7.3+2 more2020-06-19
CVE-2019-20871 [HIGH] CVE-2019-20871: An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown li An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastrophic backtracking.
nvd
CVE-2019-20842HIGHCVSS 7.2fixed in 5.9.7≥ 5.15.0, < 5.15.4+3 more2020-06-19
CVE-2019-20842 [HIGH] CWE-89 CVE-2019-20842: An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by admins via SearchAllChannels.
nvd
CVE-2020-14447HIGHCVSS 7.5fixed in 5.23.02020-06-19
CVE-2020-14447 [HIGH] CWE-835 CVE-2020-14447: An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers t An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0021.
nvd
CVE-2018-21262HIGHCVSS 7.5fixed in 4.7.32020-06-19
CVE-2018-21262 [HIGH] CWE-20 CVE-2018-21262: An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX text.
nvd
CVE-2019-20846HIGHCVSS 7.5fixed in 5.18.02020-06-19
CVE-2019-20846 [HIGH] CWE-281 CVE-2019-20846: An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local file storage.
nvd
CVE-2015-9548HIGHCVSS 7.5fixed in 1.2.02020-06-19
CVE-2015-9548 [HIGH] CWE-400 CVE-2015-9548: An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compressed file that has a large size when uncompressed.
nvd
CVE-2017-18894HIGHCVSS 8.1fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18894 [HIGH] CWE-732 CVE-2017-18894: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.
nvd
CVE-2018-21264HIGHCVSS 8.8fixed in 4.5.2≥ 4.6.0, < 4.6.2+1 more2020-06-19
CVE-2018-21264 [HIGH] CWE-20 CVE-2018-21264: An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response.
nvd
CVE-2019-20855HIGHCVSS 7.5fixed in 5.9.6≥ 5.14.0, < 5.14.5+2 more2020-06-19
CVE-2019-20855 [HIGH] CVE-2019-20855: An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows att An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sensitive information (local files) during legacy attachment migration.
nvd