Vulnerabilities > Mattermost > Mattermost Server > 8.1.7

DATE CVE VULNERABILITY TITLE RISK
2024-02-29 CVE-2024-1952 Unspecified vulnerability in Mattermost Server
Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member of.
network
low complexity
mattermost
4.3
2024-02-29 CVE-2024-1953 Allocation of Resources Without Limits or Throttling vulnerability in Mattermost Server
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, allowing an authenticated attacker to cause the server to run out of memory and crash by issuing an unusually large HTTP request.
network
low complexity
mattermost CWE-770
4.3
2024-02-29 CVE-2024-23493 Missing Authorization vulnerability in Mattermost Server
Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of. 
network
low complexity
mattermost CWE-862
6.5
2024-02-29 CVE-2024-24988 Unspecified vulnerability in Mattermost Server
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
network
low complexity
mattermost
6.5