Vulnerabilities > Mattermost > Mattermost Server > 6.6.0

DATE CVE VULNERABILITY TITLE RISK
2022-07-12 CVE-2022-2366 Incorrect Default Permissions vulnerability in Mattermost Server
Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.
network
low complexity
mattermost CWE-276
5.3
2022-06-02 CVE-2022-1982 Resource Exhaustion vulnerability in Mattermost Server
Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.
network
low complexity
mattermost CWE-400
6.5