Vulnerabilities > Mattermost > Mattermost Server > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-26 CVE-2024-47145 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.
network
low complexity
mattermost
4.3
2024-08-22 CVE-2024-42497 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems manager role with read-only access to teams to perform write operations on teams.
network
low complexity
mattermost
4.9
2024-08-22 CVE-2024-43780 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.
network
low complexity
mattermost
4.3
2024-08-01 CVE-2024-39837 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.
network
low complexity
mattermost
5.4
2024-08-01 CVE-2024-39839 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadn't been synced before.
network
low complexity
mattermost
4.3
2024-08-01 CVE-2024-41162 Unspecified vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only.
network
low complexity
mattermost
4.3
2024-08-01 CVE-2024-41926 Origin Validation Error vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote.
network
low complexity
mattermost CWE-346
4.3
2024-04-05 CVE-2024-28949 Allocation of Resources Without Limits or Throttling vulnerability in Mattermost Server
Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.
network
low complexity
mattermost CWE-770
6.5
2024-04-05 CVE-2024-2447 Origin Validation Error vulnerability in Mattermost Server
Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.
network
low complexity
mattermost CWE-346
6.5
2024-03-15 CVE-2024-2445 Cross-site Scripting vulnerability in Mattermost Server
Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to escape user-controlled outputs when generating HTML pages, which allows an attacker to perform reflected cross-site scripting attacks against the users of the Mattermost server.
network
low complexity
mattermost CWE-79
6.1