Product:

Mattermost_server

(Mattermost)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 215
Date Id Summary Products Score Patch Annotated
2020-06-19 CVE-2017-18890 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker to create a button that, when pressed by a user, launches an API request. Mattermost_server N/A
2020-06-19 CVE-2017-18876 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file. Mattermost_server N/A
2020-06-19 CVE-2017-18875 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can create arbitrary files. Mattermost_server N/A
2020-06-19 CVE-2017-18874 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal. Mattermost_server N/A
2020-06-19 CVE-2017-18873 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) via a misformatted post. Mattermost_server N/A
2020-06-19 CVE-2017-18870 An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case. Mattermost_server N/A
2020-06-19 CVE-2019-20863 An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted. Mattermost_server N/A
2020-06-19 CVE-2018-21253 An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user. Mattermost_server N/A
2020-06-19 CVE-2018-21251 An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body. Mattermost_server N/A
2020-06-19 CVE-2017-18912 An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file. Mattermost_server N/A