Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

485 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.93%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.
ModificadaAlta (8.8)0.95%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
ModificadaCrítica (9.8)1.2%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.
ModificadaAlta (8.1)0.81%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.
ModificadaCrítica (9.1)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.
ModificadaMedia (6.1)0.69%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data.
ModificadaMedia (6.1)0.69%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command.
ModificadaMedia (6.1)0.69%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of a Slack attachment.
ModificadaMedia (6.1)0.69%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the author_link field of a Slack attachment.
ModificadaMedia (4.3)0.78%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
ModificadaMedia (6.5)1.2%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.
ModificadaAlta (8.8)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response.
ModificadaMedia (4.3)0.61%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for group-message channel creation) via the Group message slash command.
ModificadaMedia (4.3)0.61%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail addresses to bypass a domain-based policy for signups.
ModificadaMedia (5.3)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) via a misformatted post.
ModificadaMedia (4.3)0.57%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.
ModificadaMedia (4.3)0.78%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions.
ModificadaMedia (5.3)0.77%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation.
ModificadaAlta (7.5)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumption) via an outgoing webhook or a slash command integration.
ModificadaMedia (4.3)0.65%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts.
ModificadaAlta (7.5)0.89%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.
ModificadaAlta (7.5)1.1%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file.
ModificadaMedia (5.3)0.81%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post.
ModificadaMedia (4.3)0.65%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Users can pin or unpin a post.
ModificadaMedia (5.3)0.77%—Mattermost Server19/6/202017/6/2026
An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.