Security Advisories for github.com/mattermost/mattermost-server in go
Critical
10 days ago
Mattermost fails to to verify the token used during code exchange
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Critical
10 days ago
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
10 days ago
Mattermost fails to sanitize team email addresses
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
19 days ago
Mattermost allows other users to determine when users had read channels via channel member objects
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
23 days ago
Mattermost allows system administrators to access password hashes and MFA secrets
go
github.com/mattermost/mattermost-server
Low
24 days ago
Mattermost allows regular users to access archived channel content and files
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
24 days ago
Mattermost does not enforce MFA on WebSocket connections
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
24 days ago
Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
24 days ago
Mattermost fails to properly restrict access to archived channel search API
go
github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Low
24 days ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Moderate
about 2 months ago
Mattermost has a Missing Authorization vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
about 2 months ago
Mattermost has an Observable Timing Discrepancy vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
about 2 months ago
Mattermost has a Missing Authorization vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
about 2 months ago
Mattermost has a Missing Authorization vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
about 2 months ago
Mattermost has an Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
about 2 months ago
Mattermost has a Missing Authorization vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
3 months ago
Mattermost boards plugin fails to restrict download access to files
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-boards
High
3 months ago
Mattermost Path Traversal vulnerability
go
github.com/mattermost/mattermost-server
Moderate
3 months ago
Mattermost makes Use of Weak Hash
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
3 months ago
Mattermost Open Redirect vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
3 months ago
Mattermost Open Redirect vulnerability
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
3 months ago
Mattermost Missing Authorization vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
4 months ago
Mattermost has Potential Server Crash due to Unvalidated Import Data
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
4 months ago
Mattermost Fails to Sanitize File Names
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago
Mattermost Fails to Sanitize Path Traversal Sequences
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
4 months ago
Mattermost Lack of Access Control Validation
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago
Mattermost Does Not Sanitize the Team Invite ID
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
4 months ago
Mattermost Server SSRF Vulnerability via the Agents Plugin
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
4 months ago
Mattermost Fails to Properly Validate Team Role Modification
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago
Mattermost Fails to Validate File Paths
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago
Mattermost Fails to Validate Remote Cluster Upload Sessions
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
5 months ago
Mattermost Path Traversal vulnerability
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
5 months ago
Mattermost has Insufficiently Protected Credentials
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
5 months ago
Mattermost Missing Authentication for Critical Function
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
5 months ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
5 months ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
6 months ago
Mattermost allows an unauthorized Guest user access to Playbook
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
6 months ago
Mattermost allows unauthorized channel member management through playbook runs
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Critical
6 months ago
Mattermost allows authenticated users to write files to arbitrary locations
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
6 months ago
Mattermost allows guest users to view information about public teams they are not members of
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
6 months ago
Mattermost allows authenticated administrator to execute LDAP search filter injection
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
8 months ago
Mattermost Fails to Restrict Certain Operations on System Admins
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
9 months ago
Mattermost allows members with permission to convert public channels to private and convert private to public
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
9 months ago
Mattermost Fails to Properly Perform Viewer Role Authorization
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
over 1 year ago
Mattermost allows team admins to promote guests to team admins
go
github.com/mattermost/mattermost-server
Low
over 1 year ago
Mattermost fails to limit the size of a request path
go
github.com/mattermost/mattermost-server
Moderate
over 1 year ago
Mattermost fails to limit the number of active sessions
go
github.com/mattermost/mattermost-server
Moderate
over 1 year ago
Mattermost crashes web clients via a malformed custom status
go
github.com/mattermost/mattermost-server
Moderate
over 1 year ago
Mattermost's detailed error messages reveal the full file path
go
github.com/mattermost/mattermost-server
Low
over 1 year ago
Mattermost fails to fully validate role changes
go
github.com/mattermost/mattermost-server
Moderate
over 2 years ago
Mattermost vulnerable to cross-site scripting (XSS)
go
github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server
Moderate
over 2 years ago
Mattermost fails to properly authentication inviter's permissions to private channel
go
github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server
Moderate
over 2 years ago
Mattermost vulnerable to information disclosure
go
github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server
Moderate
over 2 years ago
Mattermost vulnerable to information disclosure
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server/v6
Moderate
about 3 years ago
Denial of service in Mattermost
go
github.com/mattermost/mattermost-server
Moderate
about 3 years ago
Denial of service in Mattermost
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Uncontrolled Resource Consumption in Mattermost server
go
github.com/mattermost/mattermost-server
High
over 3 years ago
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server exposes team invite IDs through API endpoints
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server allows attackers to create buttons that can launch API requests
go
github.com/mattermost/mattermost-server
Critical
over 3 years ago
Mattermost Server is vulnerable to SQL Injection when executing multiple POST requests
go
github.com/mattermost/mattermost-server
High
over 3 years ago
Mattermost Server does not properly restrict use of slash commands
go
github.com/mattermost/mattermost-server
Critical
over 3 years ago
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials
go
github.com/mattermost/mattermost-server
Critical
over 3 years ago
Mattermost Server exposes OAuth personal access tokens to attackers
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server is vulnerable to webhook and slash command manipulation
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server allows users with a session ID to revoke another users' session
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server is vulnerable to XSS attacks against an OAuth 2.0 allow/deny page
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server exposes team creator's e-mail address to other members
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server has low entropy for authorization data as an OAuth 2.0 Service Provider
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server does not prevent System Admin from arbitrary file creation
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server is vulnerable to Path Traversal when files are stored locally
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server is vulnerable to XSS through author_link field in Slack attachments
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server is vulnerable to XSS through crafted links
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server is vulnerable to Directory Traversal by System Admins
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server allows XSS via redirect URL
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server allows XSS via CSRF
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server has mishandled webhook access control
go
github.com/mattermost/mattermost-server
High
over 3 years ago
Mattermost Server vulnerable to Denial of Service through `@` character prefix inserted into JavaScript field names
go
github.com/mattermost/mattermost-server
Low
over 3 years ago
Mattermost Server allows System Admin to modify LDAP account names and email addresses
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server exposes information stored by a web browser
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server's OAuth 2.0 service is vulnerable to attack through Missing Authorization
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server exposes account details to any Team Administrator
go
github.com/mattermost/mattermost-server
High
over 3 years ago
Mattermost Server does not enforce rate limits on password change attempts
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server's Session ID and Session Token are potentially compromised
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server exposes sensitive information about team URLs via an API
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server is vulnerable to XSS via a Legal or Support setting
go
github.com/mattermost/mattermost-server
High
over 3 years ago
Mattermost Server does not check if cookies are used over SSL
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener`
go
github.com/mattermost/mattermost-server
High
over 3 years ago
Mattermost Server: initial_load API exposes unnecessary information
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server exposes sensitive information via its System Console UI
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server is vulnerable to Uncontrolled Resource Consumption
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server is vulnerable to Code Injection through its LDAP fields
go
github.com/mattermost/mattermost-server
High
over 3 years ago
Mattermost Server: Insufficient Password-Reset Link Invalidation
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server is vulnerable to XSS through customizable theme color-code values
go
github.com/mattermost/mattermost-server
Moderate
over 3 years ago
Mattermost Server vulnerable to Cross-site Scripting through file preview feature
go
github.com/mattermost/mattermost-server