Vulnerabilities > Mattermost > Mattermost Server > 8.1.2

DATE CVE VULNERABILITY TITLE RISK
2024-02-29 CVE-2024-23493 Missing Authorization vulnerability in Mattermost Server
Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of. 
network
low complexity
mattermost CWE-862
6.5
2024-02-29 CVE-2024-24988 Unspecified vulnerability in Mattermost Server
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
network
low complexity
mattermost
6.5