An open API service providing security vulnerability metadata for many open source software ecosystems.

go

github.com/mattermost/mattermost-server

go

View on github.com · View on proxy.golang.org

Security Advisories for github.com/mattermost/mattermost-server in go

Moderate
28 days ago

Mattermost doesn't prevent disclosure of created user password GSA_kwCzR0hTQS13dmd2LTRmYzMtMnJjcM4ABXAE

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
28 days ago

Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation GSA_kwCzR0hTQS05cDY0LWpwYzctbTJycM4ABW__

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
28 days ago

Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin GSA_kwCzR0hTQS04Mmo2LTRmcTctZng2Ms4ABXAN

go github.com/mattermost/mattermost-plugin-calls, github.com/mattermost/mattermost-server
Moderate
28 days ago

Mattermost doesn't enforce slash command trigger-word uniqueness during command updates GSA_kwCzR0hTQS13dmN2LTl4cG0tN21xY84ABW_8

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
28 days ago

Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint GSA_kwCzR0hTQS14dmN4LW1ncGMtNXhoM84ABXAJ

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
28 days ago

Mattermost doesn't verify channel membership when processing AI-assisted message rewrites GSA_kwCzR0hTQS04cjg5LTh3MjYtY3EzMs4ABXAM

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
28 days ago

Mattermost doesn't validate the Host header when constructing response URLs for custom slash command GSA_kwCzR0hTQS12cXA1LTJtcnAtcXF4Z84ABXAG

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
28 days ago

Mattermost doesn't check the create_post channel permission during post edit operations GSA_kwCzR0hTQS12NTQ5LXh4M2MtNnBjOM4ABW_x

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
28 days ago

Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow GSA_kwCzR0hTQS1qcDNmLXg0NDktNHE3Nc4ABW_9

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
28 days ago

Mattermost doesn't validate 7zip archive structure before processing GSA_kwCzR0hTQS1jam04LWp4cHctZzQzbc4ABW_-

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
28 days ago

Mattermost does not verify remote cluster channel access when processing shared channel membership removals GSA_kwCzR0hTQS04aDl3LXc3OGMtdnZyM84ABW_6

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
28 days ago

Mattermost doesn't limit the size of the request body on the start meeting API endpoint GSA_kwCzR0hTQS1tM3AzLThmcnEtcTdxaM4ABW_4

go github.com/mattermost/mattermost-plugin-msteams-meetings, github.com/mattermost/mattermost-server
Low
28 days ago

Mattermost doesn't escape some variables that could contain malicious content during error page composition GSA_kwCzR0hTQS1qeDkzLXBmNngtODc0cs4ABW_1

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
about 2 months ago

Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement GSA_kwCzR0hTQS1taDR4LXJtcngtM2hwNM4ABVbB

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw GSA_kwCzR0hTQS1mZzM1LTVyZjYtcWczZ84ABUP4

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
3 months ago

Mattermost fails to validate user's authentication method when processing account auth type switch GSA_kwCzR0hTQS1ydjY3LTd3MmctNzk3Ns4ABTtx

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation GSA_kwCzR0hTQS1ncXY3LWoyajgtcW13cc4ABTtn

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost fails to properly enforce read permissions in search API endpoints GSA_kwCzR0hTQS1jd2ZqLTY0MmotZ2ZoNM4ABTtk

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost fails to use consistent error responses when handling the /mute command GSA_kwCzR0hTQS01bXI5LWNyY2ctOHdoMs4ABTtb

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost fails to validate team-specific upload_file permissions GSA_kwCzR0hTQS14cHZmLTZxY2MtOWpxY84ABTtc

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost allows a removed team member to enumerate all public channels within a private team GSA_kwCzR0hTQS02NzlmLXdtcmctcWY1N84ABTrr

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost fails to limit the size of responses from integration action endpoints GSA_kwCzR0hTQS0zNGc4LTlmcHAtNDZjaM4ABTr4

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost fails to preserve the redacted state of burn-on-read posts during deletion GSA_kwCzR0hTQS0zcmhyLWpyNjMtaHdxNc4ABTrg

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost fails to filter invite IDs based on user permissions GSA_kwCzR0hTQS1meDQ5LW0yNTMtMjdqas4ABTrj

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost fails to properly validate User-Agent header tokens GSA_kwCzR0hTQS0ydjN3LTZnMzUtNWY5ds4ABTra

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost fails to bound memory allocation when processing DOC files GSA_kwCzR0hTQS14djJwLXdjaGotcWpocM4ABTrT

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost allows attackers to spoof permalink embeds GSA_kwCzR0hTQS1waDIyLWZ3NW0tdzJxOc4ABTrq

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
3 months ago

Mattermost fails to properly handle very long passwords GSA_kwCzR0hTQS1tNXJ2LTU2eHgtaGZjNs4ABTrZ

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
3 months ago

Mattermost fails to bound memory allocation when processing PSD image files GSA_kwCzR0hTQS00NG12LWpxNzItZ2o0Oc4ABTrh

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
4 months ago

Mattermost fails to enforce invite permissions when updating team settings GSA_kwCzR0hTQS1jZ2pnLXAybTItcW00cM4ABSZ5

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
4 months ago

Mattermost fails to properly validate team membership when processing channel mentions GSA_kwCzR0hTQS01N2NjLTJwZjQtbWhteM4ABSZ3

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
4 months ago

Mattermost fails to sanitize sensitive data in WebSocket messages GSA_kwCzR0hTQS1wcDlqLXBmNWMtNjU5eM4ABSZo

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
4 months ago

Mattermost fails to properly validate login method restrictions GSA_kwCzR0hTQS0zYzlyLTdmMjktcXAzMs4ABSZt

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
6 months ago

Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues GSA_kwCzR0hTQS1mbXFmLXBtY20tOGN4Oc4ABQHm

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
6 months ago

Mattermost doesn't verify that post actions invoking `/share-issue-publicly` were created by the Jira plugin GSA_kwCzR0hTQS12d3c2LTc5cnYtM2o0eM4ABQHk

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
6 months ago

Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation GSA_kwCzR0hTQS14M3I4LTJobWgtODlmNc4ABP22

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost
Critical
7 months ago

Mattermost fails to to verify the token used during code exchange GSA_kwCzR0hTQS1tcDZ4LTk3eGotOXg2Ms4ABPBl

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
7 months ago

Mattermost fails to sanitize team email addresses GSA_kwCzR0hTQS00Zzg3LTl4NDUtY3gyaM4ABPBk

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Critical
7 months ago

Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication GSA_kwCzR0hTQS0zeDM5LTYyaDQtZjhqNs4ABPBh

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
7 months ago

Mattermost allows other users to determine when users had read channels via channel member objects GSA_kwCzR0hTQS05aGg3LTY1NTgtcWZwMs4ABOpf

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
7 months ago

Mattermost allows system administrators to access password hashes and MFA secrets GSA_kwCzR0hTQS1tcXA4LXBnZzUtN3g3bc4ABOjA

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
7 months ago

Mattermost allows regular users to access archived channel content and files GSA_kwCzR0hTQS14M2h4LWNoN3AtOHhnZ84ABOi8

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
7 months ago

Mattermost does not enforce MFA on WebSocket connections GSA_kwCzR0hTQS14cGc4LTh4cHYtOTQ4cM4ABOi_

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
7 months ago

Mattermost fails to properly restrict access to archived channel search API GSA_kwCzR0hTQS1qNmdnLXI1amMtNDdjbc4ABOi9

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Moderate
7 months ago

Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL GSA_kwCzR0hTQS1mZjg1LXF3M2gtZzl2cM4ABOi-

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
7 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS1tcWNqLThjMmctaDk3cc4ABOhn

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Low
8 months ago

Mattermost has an Observable Timing Discrepancy vulnerability GSA_kwCzR0hTQS14cjN3LXJtdmotZjZtN84ABNeq

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
8 months ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS0zcTRxLXdxbTYtaHZmM84ABNe5

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
8 months ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS1yNnFqLTg5NGYtNWhyMs4ABNe1

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
8 months ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS03Y3IzLTM4am0tNnA0Nc4ABNex

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
8 months ago

Mattermost has an Incorrect Authorization vulnerability GSA_kwCzR0hTQS00MjRoLXhqODctbTkzN84ABNe8

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
8 months ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS02cTdtLXA4Y2MtOTk4cs4ABNe_

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
9 months ago

Mattermost Path Traversal vulnerability GSA_kwCzR0hTQS1xeDNmLTZ2cTMtOGo4bc4ABMZt

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
9 months ago

Mattermost boards plugin fails to restrict download access to files GSA_kwCzR0hTQS1mNzJnLTUydjctbWczcM4ABMZr

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-boards
High
9 months ago

Mattermost Open Redirect vulnerability GSA_kwCzR0hTQS02OWo4LXByeDItdng5OM4ABMEQ

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
9 months ago

Mattermost makes Use of Weak Hash GSA_kwCzR0hTQS05cDkyLXg3N3ctOWZ3Ms4ABMEa

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
9 months ago

Mattermost Open Redirect vulnerability GSA_kwCzR0hTQS1obTk1LWp4NjYtZzJnaM4ABMER

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
10 months ago

Mattermost Fails to Sanitize File Names GSA_kwCzR0hTQS1wajZmLXJjOTQtZ3c1M84ABLUh

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
10 months ago

Mattermost has Potential Server Crash due to Unvalidated Import Data GSA_kwCzR0hTQS1oNDY5LTRmY2YtcDIzaM4ABLUR

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
10 months ago

Mattermost Fails to Sanitize Path Traversal Sequences GSA_kwCzR0hTQS14NjdjLXY4anItcDI5cs4ABLTm

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
10 months ago

Mattermost Fails to Validate Remote Cluster Upload Sessions GSA_kwCzR0hTQS1xNDUzLTYzOGMtaDRtcs4ABLTn

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
10 months ago

Mattermost Fails to Validate File Paths GSA_kwCzR0hTQS1ncTNyLTU4MzMtNTUzMs4ABLTi

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
10 months ago

Mattermost Fails to Properly Validate Team Role Modification GSA_kwCzR0hTQS00Mjc2LWNtOGMtNzg4aM4ABLTj

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
10 months ago

Mattermost Lack of Access Control Validation GSA_kwCzR0hTQS1wd3ZyLWdycWctN3ZwMs4ABLTo

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
10 months ago

Mattermost Does Not Sanitize the Team Invite ID GSA_kwCzR0hTQS1xajQ3LXc5ZjItcWc0NM4ABLTl

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
10 months ago

Mattermost Server SSRF Vulnerability via the Agents Plugin GSA_kwCzR0hTQS12cXdoLTVqaGgtdmM5cM4ABLTk

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
11 months ago

Mattermost has Insufficiently Protected Credentials GSA_kwCzR0hTQS00ZndqLTg1OTUtd3AyNc4ABKRo

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
11 months ago

Mattermost Path Traversal vulnerability GSA_kwCzR0hTQS13dncyLTNqaDQtNGMzOc4ABKRq

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
11 months ago

Mattermost Missing Authentication for Critical Function GSA_kwCzR0hTQS03aDM0LTljaHItNThxaM4ABKRa

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
12 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS13Z3ZwLWpqNHctODhoZs4ABJkw

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
12 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS12OGZyLXZ4bXctNm1mNs4ABJkm

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
12 months ago

Mattermost allows an unauthorized Guest user access to Playbook GSA_kwCzR0hTQS00NTc4LTZnamgtZjJqbc4ABJTD

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
12 months ago

Mattermost allows unauthorized channel member management through playbook runs GSA_kwCzR0hTQS1xd3dtLWM1ODItODJyeM4ABJTJ

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Critical
12 months ago

Mattermost allows authenticated users to write files to arbitrary locations GSA_kwCzR0hTQS1xaDU4LTl2M2otd2NqY84ABJSQ

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
about 1 year ago

Mattermost allows authenticated administrator to execute LDAP search filter injection GSA_kwCzR0hTQS00cjY3LTR4NHAtZnByZ84ABI-v

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
about 1 year ago

Mattermost allows guest users to view information about public teams they are not members of GSA_kwCzR0hTQS1qd2h3LXhmNXYtcWd4Y84ABI-z

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
about 1 year ago

Mattermost Fails to Restrict Certain Operations on System Admins GSA_kwCzR0hTQS0zMjJ2LXZoMmctcXZwds4ABGvR

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
about 1 year ago

Mattermost allows members with permission to convert public channels to private and convert private to public GSA_kwCzR0hTQS1oNXY5LXh3MmctN2hycc4ABFxA

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
about 1 year ago

Mattermost Fails to Properly Perform Viewer Role Authorization GSA_kwCzR0hTQS1mcXJxLXhteGotdjQ3eM4ABFpb

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
about 2 years ago

Mattermost fails to fully validate role changes GSA_kwCzR0hTQS01cXg5LTlmZmotNXI4Zs4AA7VE

go github.com/mattermost/mattermost-server
Low
about 2 years ago

Mattermost fails to limit the size of a request path GSA_kwCzR0hTQS1wMndxLTRnZ3AtNDVmM84AA7U_

go github.com/mattermost/mattermost-server
Moderate
about 2 years ago

Mattermost crashes web clients via a malformed custom status GSA_kwCzR0hTQS04Zjk5LWcycGoteDh3M84AA7VG

go github.com/mattermost/mattermost-server
Moderate
about 2 years ago

Mattermost's detailed error messages reveal the full file path GSA_kwCzR0hTQS12eDk3LThxOHEtcWdxNc4AA7VB

go github.com/mattermost/mattermost-server
Moderate
about 2 years ago

Mattermost fails to limit the number of active sessions GSA_kwCzR0hTQS13ajM3LW1wcTkteHJjbc4AA7VH

go github.com/mattermost/mattermost-server
Low
over 2 years ago

Mattermost Server Resource Exhaustion GSA_kwCzR0hTQS1xcWM4LXJ2MzctNzlxNc4AA6BG

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
about 3 years ago

Mattermost vulnerable to cross-site scripting (XSS) GSA_kwCzR0hTQS02M2YyLTY5NTktMnB4as4AAye3

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server
Moderate
about 3 years ago

Mattermost vulnerable to information disclosure GSA_kwCzR0hTQS04amhoLTNqZjItcGZ3cs4AAyez

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server
Moderate
about 3 years ago

Mattermost fails to properly authentication inviter's permissions to private channel GSA_kwCzR0hTQS05aGo3LXY1NmctcmhmNs4AAyey

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server
Moderate
about 3 years ago

Mattermost vulnerable to information disclosure GSA_kwCzR0hTQS0zd3E1LTNmNTYtdjV4Y84AAyex

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server/v6