Security Advisories for github.com/mattermost/mattermost/server/v8 in go
Low
5 days ago
Mattermost fails to validate user permissions in Boards
go
github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Moderate
6 days ago
Mattermost fails to validate user permissions when deleting comments in Boards
go
github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Critical
10 days ago
Mattermost fails to to verify the token used during code exchange
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Critical
10 days ago
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
10 days ago
Mattermost fails to sanitize team email addresses
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
19 days ago
Mattermost allows other users to determine when users had read channels via channel member objects
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
23 days ago
Mattermost fails to properly restrict access to archived channel search API
go
github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Moderate
23 days ago
Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
23 days ago
Mattermost does not enforce MFA on WebSocket connections
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
23 days ago
Mattermost allows regular users to access archived channel content and files
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
24 days ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Low
about 2 months ago
Mattermost has an Observable Timing Discrepancy vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
about 2 months ago
Mattermost has a Missing Authorization vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
about 2 months ago
Mattermost has a Missing Authorization vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
about 2 months ago
Mattermost has a Missing Authorization vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
about 2 months ago
Mattermost has a Missing Authorization vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
about 2 months ago
Mattermost has an Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
3 months ago
Mattermost boards plugin fails to restrict download access to files
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-boards
Low
3 months ago
Mattermost Open Redirect vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
3 months ago
Mattermost Open Redirect vulnerability
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
3 months ago
Mattermost makes Use of Weak Hash
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
3 months ago
Mattermost Missing Authorization vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
4 months ago
Mattermost Fails to Sanitize File Names
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago
Mattermost has Potential Server Crash due to Unvalidated Import Data
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
4 months ago
Mattermost Fails to Sanitize Path Traversal Sequences
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
4 months ago
Mattermost Server SSRF Vulnerability via the Agents Plugin
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
4 months ago
Mattermost Lack of Access Control Validation
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago
Mattermost Fails to Validate File Paths
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
4 months ago
Mattermost Fails to Properly Validate Team Role Modification
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago
Mattermost Fails to Validate Remote Cluster Upload Sessions
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago
Mattermost Does Not Sanitize the Team Invite ID
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
5 months ago
Mattermost has Insufficiently Protected Credentials
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
5 months ago
Mattermost Path Traversal vulnerability
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
5 months ago
Mattermost Missing Authentication for Critical Function
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
5 months ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
5 months ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
6 months ago
Mattermost allows an unauthorized Guest user access to Playbook
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
6 months ago
Mattermost allows unauthorized channel member management through playbook runs
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Critical
6 months ago
Mattermost allows authenticated users to write files to arbitrary locations
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
6 months ago
Mattermost allows guest users to view information about public teams they are not members of
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
6 months ago
Mattermost allows authenticated administrator to execute LDAP search filter injection
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
6 months ago
Mattermost fails to properly enforce access controls for guest users
go
github.com/mattermost/mattermost/server/v8
Low
6 months ago
Mattermost fails to properly enforce access control restrictions for System Manager roles
go
github.com/mattermost/mattermost/server/v8
Moderate
6 months ago
Mattermost fails to properly invalidate personal access tokens upon user deactivation
go
github.com/mattermost/mattermost/server/v8
Moderate
6 months ago
Mattermost fails to clear Google OAuth credentials
go
github.com/mattermost/mattermost/server/v8
Moderate
6 months ago
Mattermost improperly allows team administrators to modify team invites
go
github.com/mattermost/mattermost/server/v8
Moderate
7 months ago
Mattermost Fails to Verify User's Permissions When Accessing Groups
go
github.com/mattermost/mattermost/server/v8
Low
7 months ago
Mattermost Fails to Check User Access to `ExperimentalSettings`
go
github.com/mattermost/mattermost/server/v8
Moderate
7 months ago
Mattermost Fails to Validate Team Invite Permissions
go
github.com/mattermost/mattermost/server/v8
Moderate
7 months ago
Mattermost Fails to Lockout LDAP Users After Repeated Login Failures
go
github.com/mattermost/mattermost/server/v8
Moderate
8 months ago
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
go
github.com/mattermost/mattermost-plugin-playbooks, github.com/mattermost/mattermost/server/v8
Low
8 months ago
Mattermost Playbooks fails to properly validate permissions
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-playbooks
Moderate
8 months ago
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions
go
github.com/mattermost/mattermost-plugin-playbooks, github.com/mattermost/mattermost/server/v8
Moderate
8 months ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost/server/v8
Moderate
8 months ago
Mattermost vulnerable to Observable Timing Discrepancy
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-msteams
Low
8 months ago
Mattermost doesn't restrict domains LLM can request to contact upstream
go
github.com/mattermost/mattermost/server/v8
Low
8 months ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost/server/v8
Moderate
8 months ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost/server/v8
Low
8 months ago
Mattermost Missing Authentication for Critical Function
go
github.com/mattermost/mattermost/server/v8
Low
8 months ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost/server/v8
Moderate
8 months ago
Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
go
github.com/mattermost/mattermost/server/v8
Moderate
8 months ago
Mattermost Fails to Restrict Certain Operations on System Admins
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
8 months ago
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
go
github.com/mattermost/mattermost/server/v8
Moderate
9 months ago
Mattermost Fails to Enforce Certain Search APIs
go
github.com/mattermost/mattermost/server/v8
Moderate
9 months ago
Mattermost allows members with permission to convert public channels to private and convert private to public
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
9 months ago
Mattermost fail to prompt for explicit approval before adding a team admin to a private channel
go
github.com/mattermost/mattermost/server/v8
High
9 months ago
Mattermost Fails to Enforce MFA on Plugin Endpoints
go
github.com/mattermost/mattermost/server/v8
Moderate
9 months ago
Mattermost Fails to Restrict Command Execution in Archived Channels
go
github.com/mattermost/mattermost/server/v8
Moderate
9 months ago
Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels
go
github.com/mattermost/mattermost/server/v8
Moderate
9 months ago
Mattermost Fails to Properly Perform Viewer Role Authorization
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Critical
10 months ago
Mattermost allows reading arbitrary files related to importing boards
go
github.com/mattermost/mattermost/server/v8
Moderate
10 months ago
Mattermost fails to restrict channel export of archived channels
go
github.com/mattermost/mattermost/server/v8
Critical
10 months ago
Mattermost allows reading arbitrary files
go
github.com/mattermost/mattermost/server/v8
Low
10 months ago
Mattermost fails to invalidate all active sessions when converting a user to a bot
go
github.com/mattermost/mattermost/server/v8
Moderate
11 months ago
Mattermost webapp crash via a crafted post
go
github.com/mattermost/mattermost/server/v8
Moderate
11 months ago
Mattermost fails to properly validate post props
go
github.com/mattermost/mattermost/server/v8
Moderate
11 months ago
Mattermost fails to properly validate post props
go
github.com/mattermost/mattermost/server/v8
Moderate
11 months ago
Mattermost Incorrect Type Conversion or Cast
go
github.com/mattermost/mattermost/server/v8
Low
11 months ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost/server/v8
Low
11 months ago
Mattermost has Improper Check for Unusual or Exceptional Conditions
go
github.com/mattermost/mattermost/server/v8
Moderate
11 months ago
Mattermost Improper Validation of Specified Type of Input vulnerability
go
github.com/mattermost/mattermost/server/v8
Moderate
12 months ago
Mattermost Data Amplification vulnerability
go
github.com/mattermost/mattermost/server/v8
Moderate
12 months ago
Mattermost Race Condition vulnerability
go
github.com/mattermost/mattermost/server/v8
Moderate
12 months ago
Mattermost Improper Validation of Specified Type of Input vulnerability
go
github.com/mattermost/mattermost/server/v8
Moderate
about 1 year ago
Mattermost Server vulnerable to application crash from attacker-generated large response
go
github.com/mattermost/mattermost/server/v8
Moderate
about 1 year ago
Mattermost server allows authenticated user to delete arbitrary post
go
github.com/mattermost/mattermost/server/v8
Moderate
about 1 year ago
Mattermost Server allows user to get private channel names
go
github.com/mattermost/mattermost/server/v8
Moderate
about 1 year ago
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
go
github.com/mattermost/mattermost/server/v8
Low
about 1 year ago
Mattermost incorrectly issues two sessions when using desktop SSO
go
github.com/mattermost/mattermost/server/v8
Moderate
about 1 year ago
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
go
github.com/mattermost/mattermost/server/v8
High
over 1 year ago
Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams
go
github.com/mattermost/mattermost/server/v8
Moderate
over 1 year ago
Mattermost allows guest user with read access to upload files to a channel
go
github.com/mattermost/mattermost/server/v8
Moderate
over 1 year ago
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL
go
github.com/mattermost/mattermost/server/v8
Moderate
over 1 year ago
Mattermost allows remote/synthetic users to create sessions, reset passwords
go
github.com/mattermost/mattermost/server/v8
Moderate
over 1 year ago
Mattermost doesn't restrict which roles can promote a user as system admin
go
github.com/mattermost/mattermost/server/v8
Moderate
over 1 year ago
Mattermost Cross-Site Request Forgery vulnerability
go
github.com/mattermost/mattermost/server/v8
Moderate
over 1 year ago
Mattermost doesn't redact remote users' original email addresses
go
github.com/mattermost/mattermost/server/v8
Moderate
over 1 year ago
Mattermost allows a remote actor to make an arbitrary local channel read-only
go
github.com/mattermost/mattermost/server/v8
High
over 1 year ago
Mattermost allows remote actor to create/update/delete posts in arbitrary channels
go
github.com/mattermost/mattermost/server/v8
Low
over 1 year ago
Mattermost did not properly restrict channel creation
go
github.com/mattermost/mattermost/server/v8