Security Advisories for github.com/mattermost/mattermost-server in go
      
        Moderate
      
    
      
  
          19 days ago
    
    Mattermost has a Missing Authorization vulnerability
        
        go
        
        github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
      
    
      
        Low
      
    
      
  
          19 days ago
    
    Mattermost has an Observable Timing Discrepancy vulnerability
        
        go
        
        github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
      
    
      
        Moderate
      
    
      
  
          19 days ago
    
    Mattermost has a Missing Authorization vulnerability
        
        go
        
        github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
      
    
      
        High
      
    
      
  
          19 days ago
    
    Mattermost has a Missing Authorization vulnerability
        
        go
        
        github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
      
    
      
        Low
      
    
      
  
          19 days ago
    
    Mattermost has an Incorrect Authorization vulnerability
        
        go
        
        github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
      
    
      
        High
      
    
      
  
          19 days ago
    
    Mattermost has a Missing Authorization vulnerability
        
        go
        
        github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
      
    
      
        Low
      
    
      
  
          about 2 months ago
    
    Mattermost boards plugin fails to restrict download access to files
        
        go
        
        github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-boards
      
    
      
        High
      
    
      
  
          about 2 months ago
    
    Mattermost Path Traversal vulnerability
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          about 2 months ago
    
    Mattermost makes Use of Weak Hash
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Low
      
    
      
  
          about 2 months ago
    
    Mattermost Open Redirect vulnerability
        
        go
        
        github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
      
    
      
        High
      
    
      
  
          about 2 months ago
    
    Mattermost Open Redirect vulnerability
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          about 2 months ago
    
    Mattermost Missing Authorization vulnerability
        
        go
        
        github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
      
    
      
        Moderate
      
    
      
  
          2 months ago
    
    Mattermost Fails to Sanitize File Names
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          2 months ago
    
    Mattermost has Potential Server Crash due to Unvalidated Import Data
        
        go
        
        github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
      
    
      
        Moderate
      
    
      
  
          2 months ago
    
    Mattermost Fails to Sanitize Path Traversal Sequences
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          2 months ago
    
    Mattermost Fails to Validate File Paths
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          2 months ago
    
    Mattermost Fails to Validate Remote Cluster Upload Sessions
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Low
      
    
      
  
          2 months ago
    
    Mattermost Fails to Properly Validate Team Role Modification
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Low
      
    
      
  
          2 months ago
    
    Mattermost Server SSRF Vulnerability via the Agents Plugin
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          2 months ago
    
    Mattermost Does Not Sanitize the Team Invite ID
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Low
      
    
      
  
          2 months ago
    
    Mattermost Lack of Access Control Validation
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Low
      
    
      
  
          4 months ago
    
    Mattermost has Insufficiently Protected Credentials
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          4 months ago
    
    Mattermost Path Traversal vulnerability
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          4 months ago
    
    Mattermost Missing Authentication for Critical Function
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          4 months ago
    
    Mattermost Incorrect Authorization vulnerability
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          4 months ago
    
    Mattermost Incorrect Authorization vulnerability
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          5 months ago
    
    Mattermost allows an unauthorized Guest user access to Playbook
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          5 months ago
    
    Mattermost allows unauthorized channel member management through playbook runs
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Critical
      
    
      
  
          5 months ago
    
    Mattermost allows authenticated users to write files to arbitrary locations
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Low
      
    
      
  
          5 months ago
    
    Mattermost allows guest users to view information about public teams they are not members of
        
        go
        
        github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
      
    
      
        Moderate
      
    
      
  
          5 months ago
    
    Mattermost allows authenticated administrator to execute LDAP search filter injection
        
        go
        
        github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
      
    
      
        Moderate
      
    
      
  
          7 months ago
    
    Mattermost Fails to Restrict Certain Operations on System Admins
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          8 months ago
    
    Mattermost allows members with permission to convert public channels to private and convert private to public
        
        go
        
        github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
      
    
      
        Low
      
    
      
  
          over 1 year ago
    
    Mattermost allows team admins to promote guests to team admins
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 1 year ago
    
    Mattermost crashes web clients via a malformed custom status
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 1 year ago
    
    Mattermost fails to limit the number of active sessions
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 1 year ago
    
    Mattermost's detailed error messages reveal the full file path
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Low
      
    
      
  
          over 1 year ago
    
    Mattermost fails to limit the size of a request path
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Low
      
    
      
  
          over 1 year ago
    
    Mattermost fails to fully validate role changes
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 2 years ago
    
    Mattermost fails to properly authentication inviter's permissions to private channel
        
        go
        
        github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 2 years ago
    
    Mattermost vulnerable to information disclosure
        
        go
        
        github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server/v6
      
    
      
        Moderate
      
    
      
  
          over 2 years ago
    
    Mattermost vulnerable to cross-site scripting (XSS)
        
        go
        
        github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 2 years ago
    
    Mattermost vulnerable to information disclosure
        
        go
        
        github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          almost 3 years ago
    
    Denial of service in Mattermost
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          almost 3 years ago
    
    Denial of service in Mattermost
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Uncontrolled Resource Consumption in Mattermost server
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server's OAuth 2.0 service is vulnerable to attack through Missing Authorization
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server exposes information stored by a web browser
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server allows XSS via redirect URL
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server is vulnerable to XSS through crafted links
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server exposes account details to any Team Administrator
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server allows XSS via CSRF
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Low
      
    
      
  
          over 3 years ago
    
    Mattermost Server allows System Admin to modify LDAP account names and email addresses
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        High
      
    
      
  
          over 3 years ago
    
    Mattermost Server: Insufficient Password-Reset Link Invalidation
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server is vulnerable to XSS through customizable theme color-code values
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        High
      
    
      
  
          over 3 years ago
    
    Mattermost Server does not enforce rate limits on password change attempts
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        High
      
    
      
  
          over 3 years ago
    
    Mattermost Server: initial_load API exposes unnecessary information
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server is vulnerable to Uncontrolled Resource Consumption
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server's Session ID and Session Token are potentially compromised
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server is vulnerable to XSS via a Legal or Support setting
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server exposes sensitive information about team URLs via an API
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        High
      
    
      
  
          over 3 years ago
    
    Mattermost Server does not check if cookies are used over SSL
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server exposes sensitive information via its System Console UI
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener`
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server is vulnerable to Code Injection through its LDAP fields
        
        go
        
        github.com/mattermost/mattermost-server
      
    
      
        Moderate
      
    
      
  
          over 3 years ago
    
    Mattermost Server vulnerable to Cross-site Scripting through file preview feature
        
        go
        
        github.com/mattermost/mattermost-server