An open API service providing security vulnerability metadata for many open source software ecosystems.

go

github.com/mattermost/mattermost

go

View on github.com · View on proxy.golang.org

Security Advisories for github.com/mattermost/mattermost in go

Moderate
6 months ago

Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation GSA_kwCzR0hTQS14M3I4LTJobWgtODlmNc4ABP22

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost
Low
6 months ago

Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection GSA_kwCzR0hTQS1qZjVoLXhmdzQtcDhncM4ABP2N

go github.com/mattermost/mattermost-plugin-github, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Low
6 months ago

Mattermost has missing redirect URL validation GSA_kwCzR0hTQS1xNjZnLXE5OGMtcTQ1NM4ABP2Q

go github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Low
6 months ago

Mattermost fails to validate user permissions in Boards GSA_kwCzR0hTQS01OHc2LXc1NXgtNndxOM4ABPG0

go github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Moderate
6 months ago

Mattermost fails to validate user permissions when deleting comments in Boards GSA_kwCzR0hTQS1wNmdqLWpjMzgteDJtN84ABPEk

go github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Moderate
7 months ago

Mattermost fails to properly restrict access to archived channel search API GSA_kwCzR0hTQS1qNmdnLXI1amMtNDdjbc4ABOi9

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Low
7 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS1tcWNqLThjMmctaDk3cc4ABOhn

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Potential
Moderate
8 months ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS0zcTRxLXdxbTYtaHZmM84ABNe5

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Potential
Low
8 months ago

Mattermost has an Incorrect Authorization vulnerability GSA_kwCzR0hTQS00MjRoLXhqODctbTkzN84ABNe8

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Potential
High
8 months ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS02cTdtLXA4Y2MtOTk4cs4ABNe_

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Potential
High
8 months ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS1yNnFqLTg5NGYtNWhyMs4ABNe1

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Potential
Moderate
8 months ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS03Y3IzLTM4am0tNnA0Nc4ABNex

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Potential
Low
8 months ago

Mattermost has an Observable Timing Discrepancy vulnerability GSA_kwCzR0hTQS14cjN3LXJtdmotZjZtN84ABNeq

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Potential
High
9 months ago

Mattermost Path Traversal vulnerability GSA_kwCzR0hTQS1xeDNmLTZ2cTMtOGo4bc4ABMZt

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Potential
Low
9 months ago

Mattermost Open Redirect vulnerability GSA_kwCzR0hTQS1obTk1LWp4NjYtZzJnaM4ABMER

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Potential
High
9 months ago

Mattermost Open Redirect vulnerability GSA_kwCzR0hTQS02OWo4LXByeDItdng5OM4ABMEQ

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Potential
Moderate
9 months ago

Mattermost makes Use of Weak Hash GSA_kwCzR0hTQS05cDkyLXg3N3ctOWZ3Ms4ABMEa

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Potential
Low
11 months ago

Mattermost has Insufficiently Protected Credentials GSA_kwCzR0hTQS00ZndqLTg1OTUtd3AyNc4ABKRo

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Potential
Moderate
11 months ago

Mattermost Path Traversal vulnerability GSA_kwCzR0hTQS13dncyLTNqaDQtNGMzOc4ABKRq

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Potential
Moderate
11 months ago

Mattermost Missing Authentication for Critical Function GSA_kwCzR0hTQS03aDM0LTljaHItNThxaM4ABKRa

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Potential
Moderate
12 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS12OGZyLXZ4bXctNm1mNs4ABJkm

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Potential
Critical
12 months ago

Mattermost allows authenticated users to write files to arbitrary locations GSA_kwCzR0hTQS1xaDU4LTl2M2otd2NqY84ABJSQ

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Potential
Low
about 1 year ago

Mattermost allows guest users to view information about public teams they are not members of GSA_kwCzR0hTQS1qd2h3LXhmNXYtcWd4Y84ABI-z

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Potential
Moderate
about 1 year ago

Mattermost allows authenticated administrator to execute LDAP search filter injection GSA_kwCzR0hTQS00cjY3LTR4NHAtZnByZ84ABI-v

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Potential
Moderate
about 1 year ago

Mattermost fails to clear Google OAuth credentials GSA_kwCzR0hTQS04Y2d4LTljY2otM2d3cs4ABIhX

go github.com/mattermost/mattermost/server/v8
Potential
Potential
Potential
Potential
Moderate
about 1 year ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS1oNHJyLWYzN2otNGhoN84ABG1q

go github.com/mattermost/mattermost/server/v8
Potential
Potential
Low
about 1 year ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS13d2hqLXB3NmgtZjhod84ABGv_

go github.com/mattermost/mattermost/server/v8
Potential
Moderate
about 1 year ago

Mattermost Fails to Restrict Certain Operations on System Admins GSA_kwCzR0hTQS0zMjJ2LXZoMmctcXZwds4ABGvR

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Potential
Potential
Potential
Potential
Low
about 2 years ago

Mattermost fails to limit the size of a request path GSA_kwCzR0hTQS1wMndxLTRnZ3AtNDVmM84AA7U_

go github.com/mattermost/mattermost-server
Potential
Moderate
about 2 years ago

Mattermost crashes web clients via a malformed custom status GSA_kwCzR0hTQS04Zjk5LWcycGoteDh3M84AA7VG

go github.com/mattermost/mattermost-server
Potential
Moderate
about 2 years ago

Mattermost's detailed error messages reveal the full file path GSA_kwCzR0hTQS12eDk3LThxOHEtcWdxNc4AA7VB

go github.com/mattermost/mattermost-server
Potential
Moderate
about 2 years ago

Mattermost fails to limit the number of active sessions GSA_kwCzR0hTQS13ajM3LW1wcTkteHJjbc4AA7VH

go github.com/mattermost/mattermost-server
Potential
Low
about 2 years ago

Mattermost fails to fully validate role changes GSA_kwCzR0hTQS01cXg5LTlmZmotNXI4Zs4AA7VE

go github.com/mattermost/mattermost-server
Potential
Moderate
about 2 years ago

Mattermost Server Improper Access Control GSA_kwCzR0hTQS13Njd2LXBoNHgtZjQ4cc4AA6p_

go github.com/mattermost/mattermost/server/v8
Potential
Moderate
about 2 years ago

Mattermost Server doesn't limit the number of user preferences GSA_kwCzR0hTQS1tY3c2LTMyNTYtNjRnZ84AA6qB

go github.com/mattermost/mattermost/server/v8
Potential
Potential
Moderate
over 2 years ago

Mattermost notified all users in the channel when using WebSockets to respond individually GSA_kwCzR0hTQS1xN3J4LXc2NTYtZndtds4AA4Jc

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost/server/v8
Potential
Low
over 2 years ago

Mattermost allows demoted guests to change group names GSA_kwCzR0hTQS05dzk3LTlycXgtOHY0as4AA4Jd

go github.com/mattermost/mattermost/server/v8
Potential
Moderate
over 2 years ago

Mattermost vulnerable to excessive memory consumption GSA_kwCzR0hTQS13NDk2LWY1cXEtbTU4as4AA29F

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server/v6
Potential
Moderate
over 2 years ago

Mattermost password hash disclosure vulnerability GSA_kwCzR0hTQS1yNjdtLW1mN3YtcXA3as4AA29D

go github.com/mattermost/mattermost/server/v8
Potential
Moderate
about 4 years ago

Mattermost Server Sensitive Data Exposure GSA_kwCzR0hTQS1qMmgyLWN2d2gtY3I2NM4AAlGB

go github.com/mattermost/mattermost-server/v5
Potential
Moderate
about 4 years ago

Mattermost Server is vulnerable to XSS through crafted links GSA_kwCzR0hTQS1tNzhyLTJ4NnctcXFqcM4AAlDu

go github.com/mattermost/mattermost-server
Potential
Moderate
about 4 years ago

Mattermost Server exposes information stored by a web browser GSA_kwCzR0hTQS01cTM3LTk4NzQtcXhjd84AAlD_

go github.com/mattermost/mattermost-server
Potential
Potential
Potential
Potential
Potential
Potential