Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
485 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.93% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members. | |
| Modificada | Alta (8.8) | 0.95% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands. | |
| Modificada | Crítica (9.8) | 1.2% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf. | |
| Modificada | Alta (8.1) | 0.81% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens. | |
| Modificada | Crítica (9.1) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data. | |
| Modificada | Media (6.1) | 0.69% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data. | |
| Modificada | Media (6.1) | 0.69% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command. | |
| Modificada | Media (6.1) | 0.69% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of a Slack attachment. | |
| Modificada | Media (6.1) | 0.69% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the author_link field of a Slack attachment. | |
| Modificada | Media (4.3) | 0.78% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session. | |
| Modificada | Media (6.5) | 1.2% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal. | |
| Modificada | Alta (8.8) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response. | |
| Modificada | Media (4.3) | 0.61% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for group-message channel creation) via the Group message slash command. | |
| Modificada | Media (4.3) | 0.61% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail addresses to bypass a domain-based policy for signups. | |
| Modificada | Media (5.3) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) via a misformatted post. | |
| Modificada | Media (4.3) | 0.57% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider. | |
| Modificada | Media (4.3) | 0.78% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions. | |
| Modificada | Media (5.3) | 0.77% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation. | |
| Modificada | Alta (7.5) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumption) via an outgoing webhook or a slash command integration. | |
| Modificada | Media (4.3) | 0.65% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts. | |
| Modificada | Alta (7.5) | 0.89% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin. | |
| Modificada | Alta (7.5) | 1.1% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file. | |
| Modificada | Media (5.3) | 0.81% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than one post. | |
| Modificada | Media (4.3) | 0.65% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Users can pin or unpin a post. | |
| Modificada | Media (5.3) | 0.77% | — | Mattermost Server | 19/6/2020 | 17/6/2026 | An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team. |