Mattermost Server vulnerabilities
417 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
417
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH77MEDIUM288LOW36
Vulnerabilities
Page 17 of 21
CVE-2017-18903HIGHCVSS 8.8fixed in 3.9.2≥ 3.10.0, < 3.10.22020-06-19
CVE-2017-18903 [HIGH] CWE-352 CVE-2017-18903: An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.
nvd
CVE-2019-20886HIGHCVSS 7.5fixed in 5.8.02020-06-19
CVE-2019-20886 [HIGH] CWE-269 CVE-2019-20886: An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently
An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.
nvd
CVE-2017-18884HIGHCVSS 8.1fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18884 [HIGH] CWE-269 CVE-2017-18884: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.
nvd
CVE-2020-14459HIGHCVSS 7.5fixed in 5.19.02020-06-19
CVE-2020-14459 [HIGH] CWE-20 CVE-2020-14459: An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause
An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a direct message, aka MMSA-2020-0002.
nvd
CVE-2016-11069HIGHCVSS 7.5fixed in 3.2.02020-06-19
CVE-2016-11069 [HIGH] CWE-521 CVE-2016-11069: An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at pas
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
nvd
CVE-2019-20865HIGHCVSS 8.8fixed in 4.10.10≥ 5.9.0, < 5.9.2+3 more2020-06-19
CVE-2019-20865 [HIGH] CWE-352 CVE-2019-20865: An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The
An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF.
nvd
CVE-2019-20885HIGHCVSS 7.5fixed in 5.8.02020-06-19
CVE-2019-20885 [HIGH] CWE-862 CVE-2019-20885: An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt
An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file.
nvd
CVE-2019-20843HIGHCVSS 7.5fixed in 5.9.7≥ 5.15.0, < 5.15.4+3 more2020-06-19
CVE-2019-20843 [HIGH] CWE-281 CVE-2019-20843: An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permissions for configuration files.
nvd
CVE-2016-11066HIGHCVSS 7.5fixed in 3.2.02020-06-19
CVE-2016-11066 [HIGH] CWE-200 CVE-2016-11066: An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessar
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.
nvd
CVE-2016-11063MEDIUMCVSS 6.1fixed in 3.5.12020-06-19
CVE-2016-11063 [MEDIUM] CWE-79 CVE-2016-11063: An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
nvd
CVE-2016-11068MEDIUMCVSS 5.3fixed in 3.2.02020-06-19
CVE-2016-11068 [MEDIUM] CWE-74 CVE-2016-11068: An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via inje
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
nvd
CVE-2019-20887MEDIUMCVSS 4.3fixed in 4.10.6≥ 5.5.0, < 5.5.3+2 more2020-06-19
CVE-2019-20887 [MEDIUM] CWE-862 CVE-2019-20887: An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not hon
An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts.
nvd
CVE-2019-20844MEDIUMCVSS 6.5fixed in 5.9.7≥ 5.15.0, < 5.15.4+3 more2020-06-19
CVE-2019-20844 [MEDIUM] CWE-924 CVE-2019-20844: An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An at
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a direct-message channel by changing the type of a channel.
nvd
CVE-2020-14452MEDIUMCVSS 5.3fixed in 5.21.02020-06-19
CVE-2020-14452 [MEDIUM] CWE-22 CVE-2020-14452: An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTT
An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014.
nvd
CVE-2017-18899MEDIUMCVSS 5.3fixed in 4.0.5≥ 4.1.0, < 4.1.1+1 more2020-06-19
CVE-2017-18899 [MEDIUM] CWE-770 CVE-2017-18899: An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.
nvd
CVE-2016-11073MEDIUMCVSS 6.1fixed in 3.0.02020-06-19
CVE-2016-11073 [MEDIUM] CWE-79 CVE-2016-11073: An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support sett
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
nvd
CVE-2017-18876MEDIUMCVSS 4.9fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18876 [MEDIUM] CWE-732 CVE-2017-18876: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for f
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.
nvd
CVE-2017-18921MEDIUMCVSS 6.1fixed in 3.5.22020-06-19
CVE-2017-18921 [MEDIUM] CWE-79 CVE-2017-18921: An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an
An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page.
nvd
CVE-2016-11078MEDIUMCVSS 6.5fixed in 3.0.02020-06-19
CVE-2016-11078 [MEDIUM] CWE-200 CVE-2016-11078: An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain
An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI.
nvd
CVE-2019-20890MEDIUMCVSS 4.3fixed in 5.7.02020-06-19
CVE-2019-20890 [MEDIUM] CVE-2019-20890: An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discov
An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions.
nvd