Vulnerabilities > Mattermost > Mattermost Desktop

DATE CVE VULNERABILITY TITLE RISK
2024-09-16 CVE-2024-39772 Unspecified vulnerability in Mattermost Desktop
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
network
low complexity
mattermost
5.3
2024-09-16 CVE-2024-45835 Unspecified vulnerability in Mattermost Desktop
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
network
low complexity
mattermost
6.5
2024-09-16 CVE-2024-39613 Uncontrolled Search Path Element vulnerability in Mattermost Desktop
Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.
local
low complexity
mattermost CWE-427
7.8
2024-06-14 CVE-2024-36287 Unspecified vulnerability in Mattermost Desktop
Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.
local
low complexity
mattermost
3.3
2024-06-14 CVE-2024-37182 Unspecified vulnerability in Mattermost Desktop
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
network
low complexity
mattermost
6.1
2023-11-02 CVE-2023-5875 Unspecified vulnerability in Mattermost Desktop
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server
network
low complexity
mattermost
5.3
2023-11-02 CVE-2023-5876 Unspecified vulnerability in Mattermost Desktop
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
network
high complexity
mattermost
5.3
2023-11-02 CVE-2023-5920 Unspecified vulnerability in Mattermost Desktop
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.
local
low complexity
mattermost
3.3
2023-10-17 CVE-2023-5339 Information Exposure Through Log Files vulnerability in Mattermost Desktop
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. 
local
low complexity
mattermost CWE-532
5.5
2023-05-02 CVE-2023-2000 Open Redirect vulnerability in Mattermost Desktop
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
network
low complexity
mattermost CWE-601
5.4