Vulnerabilities > Mattermost > Mattermost Server > 9.5.1

DATE CVE VULNERABILITY TITLE RISK
2024-08-01 CVE-2024-39839 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadn't been synced before.
network
low complexity
mattermost
4.3
2024-08-01 CVE-2024-41144 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled,  which allows a malicious remote to create/update/delete arbitrary posts in arbitrary channels
network
low complexity
mattermost
7.1
2024-08-01 CVE-2024-41162 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only.
network
low complexity
mattermost
4.3
2024-08-01 CVE-2024-41926 Origin Validation Error vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote.
network
low complexity
mattermost CWE-346
4.3
2024-04-26 CVE-2024-22091 Allocation of Resources Without Limits or Throttling vulnerability in Mattermost Server
Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user inputs which allows an attacker to cause excessive resource consumption, possibly leading to a DoS via sending large request paths
network
low complexity
mattermost CWE-770
6.5
2024-04-26 CVE-2024-32046 Information Exposure Through an Error Message vulnerability in Mattermost Server
Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored
network
low complexity
mattermost CWE-209
4.3
2024-04-26 CVE-2024-4182 Improper Check for Unusual or Exceptional Conditions vulnerability in Mattermost Server
Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
network
low complexity
mattermost CWE-754
4.3
2024-04-26 CVE-2024-4183 Allocation of Resources Without Limits or Throttling vulnerability in Mattermost Server
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
network
low complexity
mattermost CWE-770
6.5
2024-04-26 CVE-2024-4195 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guests to team admins via crafted HTTP requests.
network
low complexity
mattermost
2.7
2024-04-26 CVE-2024-4198 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.
network
low complexity
mattermost
2.7