Vulnerabilities > Mattermost > Mattermost Mobile > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-16 CVE-2024-45833 Unspecified vulnerability in Mattermost Mobile 1.26.0/1.29.0/1.30.0
Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the password contains a special character..
network
low complexity
mattermost
6.5
2024-07-15 CVE-2024-32945 Missing Initialization of Resource vulnerability in Mattermost Mobile 1.26.0/1.29.0/1.30.0
Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
network
low complexity
mattermost CWE-909
5.3
2024-07-15 CVE-2024-39767 Improper Authentication vulnerability in Mattermost Mobile 1.26.0/1.29.0/1.30.0
Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.
network
low complexity
mattermost CWE-287
6.5
2024-04-16 CVE-2024-3872 Unspecified vulnerability in Mattermost Mobile
Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.
network
low complexity
mattermost
6.5
2024-03-15 CVE-2024-24975 Unspecified vulnerability in Mattermost Mobile
Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the syntax highlighter, allowing an attacker to send a very large code block and crash the mobile app.
network
low complexity
mattermost
6.5
2020-06-19 CVE-2019-20850 Incomplete Cleanup vulnerability in Mattermost Mobile
An issue was discovered in Mattermost Mobile Apps before 1.26.0.
network
low complexity
mattermost CWE-459
5.3
2020-06-19 CVE-2019-20849 Incomplete Cleanup vulnerability in Mattermost Mobile
An issue was discovered in Mattermost Mobile Apps before 1.26.0.
network
low complexity
mattermost CWE-459
5.3