Vulnerabilities > Mattermost > Mattermost Server > 7.8.6

DATE CVE VULNERABILITY TITLE RISK
2023-07-17 CVE-2023-3585 Resource Exhaustion vulnerability in Mattermost Server
Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.
network
low complexity
mattermost CWE-400
4.3
2023-07-17 CVE-2023-3586 Incorrect Authorization vulnerability in Mattermost Server
Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared public Boards to remain accessible.
network
low complexity
mattermost CWE-863
5.4
2023-07-17 CVE-2023-3587 Missing Authorization vulnerability in Mattermost Server
Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any user with a valid sharing link to join the board with editor access, without the UI showing the updated permissions.
network
low complexity
mattermost CWE-862
2.7
2023-07-17 CVE-2023-3591 Improper Authentication vulnerability in Mattermost Server
Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.
network
low complexity
mattermost CWE-287
8.2
2023-07-17 CVE-2023-3593 Unspecified vulnerability in Mattermost Server
Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input.
network
low complexity
mattermost
6.5
2023-07-17 CVE-2023-3614 Resource Exhaustion vulnerability in Mattermost Server
Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server resources, making the server unresponsive for an extended period of time by linking to specially crafted image file.
local
low complexity
mattermost CWE-400
3.3
2023-04-25 CVE-2023-2281 Unspecified vulnerability in Mattermost Server
When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients.
network
low complexity
mattermost
4.3