github.com/mattermost/mattermost-server
Go296 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/mattermost/mattermost-serverpage 1 of 6
- CVE-2016-11063MEDIUMCVSS 6.1EG 6.1fixed in 3.5.1 or 3.5.1+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
- CVE-2016-11066HIGHCVSS 7.5EG 7.5fixed in 3.1.12020-06-19
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.
- CVE-2016-11067MEDIUMCVSS 5.3EG 5.3fixed in 3.2.0 or 3.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.
- CVE-2016-11068MEDIUMCVSS 5.3EG 5.3fixed in 3.2.0 or 3.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
- CVE-2016-11069HIGHCVSS 7.5EG 7.5fixed in 3.2.0 or 3.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
- CVE-2016-11070MEDIUMCVSS 5.4EG 5.4fixed in 3.1.0 or 3.1.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
- CVE-2016-11071MEDIUMCVSS 6.1EG 6.1fixed in 3.1.0 or 3.1.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.
- CVE-2016-11072MEDIUMCVSS 6.5EG 6.5fixed in 3.0.2 or 3.0.2+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.
- CVE-2016-11073MEDIUMCVSS 6.1EG 6.1fixed in 3.0.0 or 3.0.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
- CVE-2016-11074CRITICALCVSS 9.8EG 9.8fixed in 3.0.0 or 3.0.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
- CVE-2016-11075MEDIUMCVSS 5.3EG 5.3fixed in 2.0.1-0.20160310160916-26ad6d2c76962020-06-19
An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API.
- CVE-2016-11076MEDIUMCVSS 5.3EG 5.3fixed in 3.0.0 or 3.0.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
- CVE-2016-11077LOWCVSS 2.7EG 2.7fixed in 3.0.0 or 3.0.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change the account name and e-mail address of an LDAP account.
- CVE-2016-11078MEDIUMCVSS 6.5EG 6.5fixed in 3.0.0 or 3.0.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI.
- CVE-2016-11079MEDIUMCVSS 6.1EG 6.1fixed in 3.0.0 or 3.0.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.
- CVE-2016-11080MEDIUMCVSS 4.3EG 4.3fixed in 3.0.0 or 3.0.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view account details.
- CVE-2016-11081MEDIUMCVSS 4.3EG 4.3fixed in 2.2.0 or 2.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web browser.
- CVE-2016-11082MEDIUMCVSS 6.1EG 6.1fixed in 2.2.0 or 2.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
- CVE-2016-11083MEDIUMCVSS 6.1EG 6.1fixed in 2.2.0 or 2.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.
- CVE-2016-11084MEDIUMCVSS 6.1EG 6.1fixed in 2.1.0 or 2.1.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
- CVE-2017-18870MEDIUMCVSS 4.3EG 4.32020-06-19
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case.
- CVE-2017-18871HIGHCVSS 7.5EG 7.5fixed in 4.2.2, 4.3.4, 4.4.5, 4.5.0, 4.2.2+incompatible, 4.3.4+incompatible, 4.4.5+incompatible or 4.5.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denial of service (application crash) via an @ character before a JavaScript field name.
- CVE-2017-18872MEDIUMCVSS 4.3EG 4.3fixed in 4.3.3, 4.4.3, 4.3.3+incompatible or 4.4.3+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.
- CVE-2017-18873MEDIUMCVSS 5.3EG 5.3fixed in 4.1.2-0.20171013141717-ee57a5829ab1, 4.2.1-0.20171013140502-b3e4b0ac9168, 4.3.0, 4.1.2-0.20171013141717-ee57a5829ab1+incompatible, 4.2.1-0.20171013140502-b3e4b0ac9168+incompatible or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) via a misformatted post.
- CVE-2017-18874MEDIUMCVSS 6.5EG 6.5fixed in 4.1.2-0.20171004201910-6be8113eb60, 4.2.1-0.20171004194140-6d3cb2ce07fc, 4.3.0, 4.2.0+incompatible or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.
- CVE-2017-18875MEDIUMCVSS 4.9EG 4.9fixed in 4.1.2-0.20171004201910-6be8113eb60c, 4.2.1-0.20171004194140-6d3cb2ce07fc, 4.3.0 or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can create arbitrary files.
- CVE-2017-18876MEDIUMCVSS 4.9EG 4.9fixed in 4.1.2-0.20171004201910-6be8113eb60c, 4.2.1-0.20171004194140-6d3cb2ce07fc, 4.3.0 or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.
- CVE-2017-18877MEDIUMCVSS 6.1EG 6.1fixed in 4.1.2, 4.2.1, 4.3.0, 4.1.2+incompatible, 4.2.1+incompatible or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page.
- CVE-2017-18878MEDIUMCVSS 4.3EG 4.3fixed in 4.1.2-0.20171004201910-6be8113eb60c, 4.2.1-0.20171004192657-8fbbd688ea24, 4.3.0 or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
- CVE-2017-18879MEDIUMCVSS 6.1EG 6.1fixed in 4.1.2, 4.2.1, 4.3.0, 4.1.2+incompatible, 4.2.1+incompatible or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the author_link field of a Slack attachment.
- CVE-2017-18883CRITICALCVSS 9.1EG 9.1fixed in 4.1.2, 4.2.1, 4.3.0, 4.1.2+incompatible, 4.2.1+incompatible or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.
- CVE-2017-18884HIGHCVSS 8.1EG 8.1fixed in 4.1.2, 4.2.1, 4.3.0, 4.1.2+incompatible, 4.2.1+incompatible or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.
- CVE-2017-18885CRITICALCVSS 9.8EG 9.8fixed in 4.1.2, 4.2.1, 4.3.0, 4.1.2+incompatible, 4.2.1+incompatible or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.
- CVE-2017-18886HIGHCVSS 8.8EG 8.8fixed in 4.1.2, 4.2.1, 4.3.0, 4.1.2+incompatible, 4.2.1+incompatible or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
- CVE-2017-18887MEDIUMCVSS 5.3EG 5.3fixed in 4.1.2, 4.2.1, 4.3.0, 4.1.2+incompatible, 4.2.1+incompatible or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.
- CVE-2017-18888CRITICALCVSS 9.8EG 9.8fixed in 4.1.2, 4.2.1, 4.3.0, 4.1.2+incompatible, 4.2.1+incompatible or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.
- CVE-2017-18889MEDIUMCVSS 4.3EG 4.3fixed in 4.1.2, 4.2.1, 4.3.0, 4.1.2+incompatible, 4.2.1+incompatible or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could create fictive system-message posts via webhooks and slash commands, in the v3 or v4 REST API.
- CVE-2017-18890MEDIUMCVSS 4.3EG 4.3fixed in 4.1.2, 4.2.1, 4.3.0, 4.1.2+incompatible, 4.2.1+incompatible or 4.3.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker to create a button that, when pressed by a user, launches an API request.
- CVE-2017-18891MEDIUMCVSS 6.1EG 6.1fixed in 4.0.5, 4.1.1, 4.2.0, 4.0.5+incompatible, 4.1.1+incompatible or 4.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
- CVE-2017-18892MEDIUMCVSS 6.1EG 6.1fixed in 4.0.5, 4.1.1, 4.2.0, 4.0.5+incompatible, 4.1.1+incompatible or 4.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.
- CVE-2017-18893MEDIUMCVSS 6.1EG 6.1fixed in 4.0.5, 4.1.1, 4.2.0, 4.0.5+incompatible, 4.1.1+incompatible or 4.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.
- CVE-2017-18894HIGHCVSS 8.1EG 8.1fixed in 4.0.5, 4.1.1, 4.2.0, 4.0.5+incompatible, 4.1.1+incompatible or 4.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.
- CVE-2017-18895MEDIUMCVSS 5.3EG 5.3fixed in 4.0.5, 4.1.1, 4.2.0, 4.0.5+incompatible, 4.1.1+incompatible or 4.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive information (user statuses) via a REST API version 4 endpoint.
- CVE-2017-18896MEDIUMCVSS 5.3EG 5.3fixed in 4.1.1, 4.0.5, 4.2.0, 4.0.5+incompatible, 4.1.1+incompatible or 4.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint.
- CVE-2017-18897MEDIUMCVSS 6.1EG 6.1fixed in 4.0.5, 4.1.1, 4.2.0, 4.0.5+incompatible, 4.1.1+incompatible or 4.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.
- CVE-2017-18898MEDIUMCVSS 5.3EG 5.3fixed in 4.0.5, 4.1.1, 4.2.0, 4.0.5+incompatible, 4.1.1+incompatible or 4.2.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially cause a web browser to hang.
- CVE-2017-18900CRITICALCVSS 9.8EG 9.8fixed in 3.10.3, 4.0.3, 3.10.3+incompatible or 4.0.3+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.
- CVE-2017-18901MEDIUMCVSS 5.3EG 5.3fixed in 3.10.3 or 4.0.4, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team invite ID by requesting a JSON document.
- CVE-2017-18902MEDIUMCVSS 5.3EG 5.3fixed in 3.10.3, 4.0.4, 4.1.0, 3.10.3+incompatible, 4.0.4+incompatible or 4.1.0+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints.
- CVE-2017-18903HIGHCVSS 8.8EG 8.8fixed in 3.9.2, 3.10.2, 3.9.2+incompatible or 3.10.2+incompatible, by version range2020-06-19
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.
Check whether github.com/mattermost/mattermost-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/mattermost/mattermost-server CVEs against the assets you own.
Book a Demo →