Vulnerabilities > Mattermost > Mattermost Server > 9.8.0

DATE CVE VULNERABILITY TITLE RISK
2024-08-22 CVE-2024-42497 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems manager role with read-only access to teams to perform write operations on teams.
network
low complexity
mattermost
4.9
2024-08-22 CVE-2024-43780 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.
network
low complexity
mattermost
4.3
2024-08-01 CVE-2024-39839 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadn't been synced before.
network
low complexity
mattermost
4.3
2024-08-01 CVE-2024-41144 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled,  which allows a malicious remote to create/update/delete arbitrary posts in arbitrary channels
network
low complexity
mattermost
7.1
2024-08-01 CVE-2024-41162 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only.
network
low complexity
mattermost
4.3