An open API service providing security vulnerability metadata for many open source software ecosystems.

go

github.com/mattermost/mattermost/server/v8

go

View on github.com · View on proxy.golang.org

Security Advisories for github.com/mattermost/mattermost/server/v8 in go

Low
5 days ago

Mattermost fails to validate user permissions in Boards GSA_kwCzR0hTQS01OHc2LXc1NXgtNndxOM4ABPG0

go github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Moderate
6 days ago

Mattermost fails to validate user permissions when deleting comments in Boards GSA_kwCzR0hTQS1wNmdqLWpjMzgteDJtN84ABPEk

go github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Critical
10 days ago

Mattermost fails to to verify the token used during code exchange GSA_kwCzR0hTQS1tcDZ4LTk3eGotOXg2Ms4ABPBl

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Critical
10 days ago

Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication GSA_kwCzR0hTQS0zeDM5LTYyaDQtZjhqNs4ABPBh

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
10 days ago

Mattermost fails to sanitize team email addresses GSA_kwCzR0hTQS00Zzg3LTl4NDUtY3gyaM4ABPBk

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
19 days ago

Mattermost allows other users to determine when users had read channels via channel member objects GSA_kwCzR0hTQS05aGg3LTY1NTgtcWZwMs4ABOpf

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
23 days ago

Mattermost fails to properly restrict access to archived channel search API GSA_kwCzR0hTQS1qNmdnLXI1amMtNDdjbc4ABOi9

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Moderate
23 days ago

Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL GSA_kwCzR0hTQS1mZjg1LXF3M2gtZzl2cM4ABOi-

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
23 days ago

Mattermost does not enforce MFA on WebSocket connections GSA_kwCzR0hTQS14cGc4LTh4cHYtOTQ4cM4ABOi_

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
23 days ago

Mattermost allows regular users to access archived channel content and files GSA_kwCzR0hTQS14M2h4LWNoN3AtOHhnZ84ABOi8

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
24 days ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS1tcWNqLThjMmctaDk3cc4ABOhn

go github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Low
about 2 months ago

Mattermost has an Observable Timing Discrepancy vulnerability GSA_kwCzR0hTQS14cjN3LXJtdmotZjZtN84ABNeq

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
about 2 months ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS1yNnFqLTg5NGYtNWhyMs4ABNe1

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
about 2 months ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS02cTdtLXA4Y2MtOTk4cs4ABNe_

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
about 2 months ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS0zcTRxLXdxbTYtaHZmM84ABNe5

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
about 2 months ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS03Y3IzLTM4am0tNnA0Nc4ABNex

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
about 2 months ago

Mattermost has an Incorrect Authorization vulnerability GSA_kwCzR0hTQS00MjRoLXhqODctbTkzN84ABNe8

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
3 months ago

Mattermost boards plugin fails to restrict download access to files GSA_kwCzR0hTQS1mNzJnLTUydjctbWczcM4ABMZr

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-boards
Low
3 months ago

Mattermost Open Redirect vulnerability GSA_kwCzR0hTQS1obTk1LWp4NjYtZzJnaM4ABMER

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
3 months ago

Mattermost Open Redirect vulnerability GSA_kwCzR0hTQS02OWo4LXByeDItdng5OM4ABMEQ

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
3 months ago

Mattermost makes Use of Weak Hash GSA_kwCzR0hTQS05cDkyLXg3N3ctOWZ3Ms4ABMEa

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
3 months ago

Mattermost Missing Authorization vulnerability GSA_kwCzR0hTQS0zdmNtLWM0MnAtM2hoZs4ABMEP

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
4 months ago

Mattermost Fails to Sanitize File Names GSA_kwCzR0hTQS1wajZmLXJjOTQtZ3c1M84ABLUh

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago

Mattermost has Potential Server Crash due to Unvalidated Import Data GSA_kwCzR0hTQS1oNDY5LTRmY2YtcDIzaM4ABLUR

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
4 months ago

Mattermost Fails to Sanitize Path Traversal Sequences GSA_kwCzR0hTQS14NjdjLXY4anItcDI5cs4ABLTm

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
4 months ago

Mattermost Server SSRF Vulnerability via the Agents Plugin GSA_kwCzR0hTQS12cXdoLTVqaGgtdmM5cM4ABLTk

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
4 months ago

Mattermost Lack of Access Control Validation GSA_kwCzR0hTQS1wd3ZyLWdycWctN3ZwMs4ABLTo

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago

Mattermost Fails to Validate File Paths GSA_kwCzR0hTQS1ncTNyLTU4MzMtNTUzMs4ABLTi

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
4 months ago

Mattermost Fails to Properly Validate Team Role Modification GSA_kwCzR0hTQS00Mjc2LWNtOGMtNzg4aM4ABLTj

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago

Mattermost Fails to Validate Remote Cluster Upload Sessions GSA_kwCzR0hTQS1xNDUzLTYzOGMtaDRtcs4ABLTn

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago

Mattermost Does Not Sanitize the Team Invite ID GSA_kwCzR0hTQS1xajQ3LXc5ZjItcWc0NM4ABLTl

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
5 months ago

Mattermost has Insufficiently Protected Credentials GSA_kwCzR0hTQS00ZndqLTg1OTUtd3AyNc4ABKRo

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
5 months ago

Mattermost Path Traversal vulnerability GSA_kwCzR0hTQS13dncyLTNqaDQtNGMzOc4ABKRq

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
5 months ago

Mattermost Missing Authentication for Critical Function GSA_kwCzR0hTQS03aDM0LTljaHItNThxaM4ABKRa

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
5 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS13Z3ZwLWpqNHctODhoZs4ABJkw

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
5 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS12OGZyLXZ4bXctNm1mNs4ABJkm

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
6 months ago

Mattermost allows an unauthorized Guest user access to Playbook GSA_kwCzR0hTQS00NTc4LTZnamgtZjJqbc4ABJTD

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
6 months ago

Mattermost allows unauthorized channel member management through playbook runs GSA_kwCzR0hTQS1xd3dtLWM1ODItODJyeM4ABJTJ

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Critical
6 months ago

Mattermost allows authenticated users to write files to arbitrary locations GSA_kwCzR0hTQS1xaDU4LTl2M2otd2NqY84ABJSQ

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
6 months ago

Mattermost allows guest users to view information about public teams they are not members of GSA_kwCzR0hTQS1qd2h3LXhmNXYtcWd4Y84ABI-z

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
6 months ago

Mattermost allows authenticated administrator to execute LDAP search filter injection GSA_kwCzR0hTQS00cjY3LTR4NHAtZnByZ84ABI-v

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
6 months ago

Mattermost fails to clear Google OAuth credentials GSA_kwCzR0hTQS04Y2d4LTljY2otM2d3cs4ABIhX

go github.com/mattermost/mattermost/server/v8
Moderate
7 months ago

Mattermost Fails to Validate Team Invite Permissions GSA_kwCzR0hTQS1yN3IyLW0zdnItYzhxY84ABH4U

go github.com/mattermost/mattermost/server/v8
Moderate
8 months ago

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type GSA_kwCzR0hTQS0zZzM2LWdmN2MtNzVxd84ABHIQ

go github.com/mattermost/mattermost-plugin-playbooks, github.com/mattermost/mattermost/server/v8
Low
8 months ago

Mattermost Playbooks fails to properly validate permissions GSA_kwCzR0hTQS1mcjIyLTUzNzctZjNwN84ABHIO

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-playbooks
Moderate
8 months ago

Mattermost Playbooks fails to validate the uniqueness and quantity of task actions GSA_kwCzR0hTQS02ODljLXhxN3gteGp3Zs4ABHIK

go github.com/mattermost/mattermost-plugin-playbooks, github.com/mattermost/mattermost/server/v8
Moderate
8 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS1tajJwLXYyYzItdmg0ds4ABG5Q

go github.com/mattermost/mattermost/server/v8
Moderate
8 months ago

Mattermost vulnerable to Observable Timing Discrepancy GSA_kwCzR0hTQS0yajg3LXA2MjMtOGNjMs4ABG1v

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-msteams
Low
8 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS1qNjM5LW0zNjctNzVjZs4ABG1o

go github.com/mattermost/mattermost/server/v8
Moderate
8 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS1oNHJyLWYzN2otNGhoN84ABG1q

go github.com/mattermost/mattermost/server/v8
Low
8 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS13d2hqLXB3NmgtZjhod84ABGv_

go github.com/mattermost/mattermost/server/v8
Moderate
8 months ago

Mattermost Fails to Restrict Certain Operations on System Admins GSA_kwCzR0hTQS0zMjJ2LXZoMmctcXZwds4ABGvR

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
9 months ago

Mattermost Fails to Enforce Certain Search APIs GSA_kwCzR0hTQS0zZ3B4LXA2M3AtcHI1cs4ABFxB

go github.com/mattermost/mattermost/server/v8
Moderate
9 months ago

Mattermost allows members with permission to convert public channels to private and convert private to public GSA_kwCzR0hTQS1oNXY5LXh3MmctN2hycc4ABFxA

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
High
9 months ago

Mattermost Fails to Enforce MFA on Plugin Endpoints GSA_kwCzR0hTQS03MnF2LWo4dnIteHZmds4ABFw7

go github.com/mattermost/mattermost/server/v8
Moderate
9 months ago

Mattermost Fails to Properly Perform Viewer Role Authorization GSA_kwCzR0hTQS1mcXJxLXhteGotdjQ3eM4ABFpb

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Critical
10 months ago

Mattermost allows reading arbitrary files GSA_kwCzR0hTQS12NDY5LTd3cDYtN2N2cM4ABEuB

go github.com/mattermost/mattermost/server/v8
Moderate
11 months ago

Mattermost webapp crash via a crafted post GSA_kwCzR0hTQS13NnhoLWM4MnctaDk5N84ABDca

go github.com/mattermost/mattermost/server/v8
Moderate
11 months ago

Mattermost fails to properly validate post props GSA_kwCzR0hTQS00NXY5LXc5ZmgtMzNqNs4ABDao

go github.com/mattermost/mattermost/server/v8
Moderate
11 months ago

Mattermost fails to properly validate post props GSA_kwCzR0hTQS01bTdqLTZnYzQtZmY1Z84ABDah

go github.com/mattermost/mattermost/server/v8
Moderate
11 months ago

Mattermost Incorrect Type Conversion or Cast GSA_kwCzR0hTQS04ajNxLWdjOXgtNzk3Ms4ABDZg

go github.com/mattermost/mattermost/server/v8
Low
11 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS1xOGZnLWNwM3EtNWp3bc4ABDHt

go github.com/mattermost/mattermost/server/v8
Moderate
12 months ago

Mattermost Data Amplification vulnerability GSA_kwCzR0hTQS12NjQ3LWg4amotZnc1cs4ABCdp

go github.com/mattermost/mattermost/server/v8
Moderate
12 months ago

Mattermost Race Condition vulnerability GSA_kwCzR0hTQS04MjZoLXA0YzMtNDc3cM4ABCdm

go github.com/mattermost/mattermost/server/v8
Moderate
about 1 year ago

Mattermost Server allows user to get private channel names GSA_kwCzR0hTQS02bXZwLWdoNzctN3Z3aM4ABAwn

go github.com/mattermost/mattermost/server/v8
Moderate
over 1 year ago

Mattermost Cross-Site Request Forgery vulnerability GSA_kwCzR0hTQS1ocmY5LXJtOTUtZnBmM84AA-4D

go github.com/mattermost/mattermost/server/v8
Low
over 1 year ago

Mattermost did not properly restrict channel creation GSA_kwCzR0hTQS12dnBnLTU1cDctNWg4d84AA-UY

go github.com/mattermost/mattermost/server/v8