Vulnerabilities > Mattermost > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-12 | CVE-2023-2515 | Incorrect Authorization vulnerability in Mattermost Server Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin | 8.8 |
2023-04-17 | CVE-2023-1831 | Cleartext Transmission of Sensitive Information vulnerability in Mattermost Server Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config). | 7.5 |
2022-05-03 | CVE-2022-1548 | Unspecified vulnerability in Mattermost Playbooks Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membership privileges and perform actions restricted to playbook admins. | 8.8 |
2022-04-19 | CVE-2022-1384 | Missing Authorization vulnerability in Mattermost Server Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known vulnerabilities. | 8.8 |
2022-03-10 | CVE-2022-0903 | Out-of-bounds Write vulnerability in Mattermost Server A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body. | 7.5 |
2022-01-18 | CVE-2021-37866 | Insufficient Session Expiration vulnerability in Mattermost Boards 0.10.0 Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization. | 7.5 |
2021-12-09 | CVE-2021-37861 | Information Exposure Through Log Files vulnerability in Mattermost Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails. | 7.5 |
2020-06-26 | CVE-2020-13891 | Unspecified vulnerability in Mattermost An issue was discovered in Mattermost Mobile Apps before 1.31.2 on iOS. | 7.5 |
2020-06-19 | CVE-2017-18917 | Use of Password Hash With Insufficient Computational Effort vulnerability in Mattermost Server An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. | 7.5 |
2020-06-19 | CVE-2017-18906 | Improper Authentication vulnerability in Mattermost Server An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. | 8.1 |