Vulnerabilities > Mattermost > Mattermost Server > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-12 | CVE-2023-2515 | Incorrect Authorization vulnerability in Mattermost Server Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin | 8.8 |
2023-04-17 | CVE-2023-1831 | Cleartext Transmission of Sensitive Information vulnerability in Mattermost Server Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config). | 7.5 |
2022-04-19 | CVE-2022-1384 | Missing Authorization vulnerability in Mattermost Server Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known vulnerabilities. | 8.8 |
2022-03-10 | CVE-2022-0903 | Out-of-bounds Write vulnerability in Mattermost Server A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body. | 7.5 |
2020-06-19 | CVE-2017-18917 | Use of Password Hash With Insufficient Computational Effort vulnerability in Mattermost Server An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. | 7.5 |
2020-06-19 | CVE-2017-18906 | Improper Authentication vulnerability in Mattermost Server An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. | 8.1 |
2020-06-19 | CVE-2016-11069 | Weak Password Requirements vulnerability in Mattermost Server An issue was discovered in Mattermost Server before 3.2.0. | 7.5 |
2020-06-19 | CVE-2016-11066 | Information Exposure vulnerability in Mattermost Server An issue was discovered in Mattermost Server before 3.2.0. | 7.5 |
2020-06-19 | CVE-2015-9548 | Resource Exhaustion vulnerability in Mattermost Server An issue was discovered in Mattermost Server before 1.2.0. | 7.5 |
2020-06-19 | CVE-2017-18909 | Improper Certificate Validation vulnerability in Mattermost Server An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. | 7.5 |