An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.

Top 2.2% on proxy.golang.org
Top 4.2% dependent packages on proxy.golang.org
Top 4.7% dependent repos on proxy.golang.org
Top 0.1% forks on proxy.golang.org
Top 2.2% docker downloads on proxy.golang.org

proxy.golang.org : github.com/mattermost/mattermost/server/v8

Mattermost is an open source platform for secure collaboration across the entire software development lifecycle..

Registry - Source - Documentation - JSON - codemeta.json
purl: pkg:golang/github.com/mattermost/mattermost/server/v8
Keywords: collaboration , golang , hacktoberfest , mattermost , monorepo , react , react-native
License: GPL-1.0+
Latest release: almost 2 years ago
First release: about 2 years ago
Namespace: github.com/mattermost/mattermost/server
Dependent packages: 2
Dependent repositories: 1
Stars: 34,281 on GitHub
Forks: 8,105 on GitHub
Docker dependents: 20
Docker downloads: 444,355,188
Total Commits: 16730
Committers: 1084
Average commits per author: 15.434
Development Distribution Score (DDS): 0.924
More commit stats: commits.ecosyste.ms
See more repository details: repos.ecosyste.ms
Last synced: 1 day ago

Low
GSA_kwCzR0hTQS05aGg3LTY1NTgtcWZwMs4ABOpf
Mattermost allows other users to determine when users had read channels via channel member objects
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 11 days ago
Moderate
GSA_kwCzR0hTQS1tcXA4LXBnZzUtN3g3bc4ABOjA
Mattermost allows system administrators to access password hashes and MFA secrets
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 15 days ago
Moderate
GSA_kwCzR0hTQS1qNmdnLXI1amMtNDdjbc4ABOi9
Mattermost fails to properly restrict access to archived channel search API
Ecosystems: go
Packages: github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Source: github
Published: 15 days ago
Low
GSA_kwCzR0hTQS14M2h4LWNoN3AtOHhnZ84ABOi8
Mattermost allows regular users to access archived channel content and files
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 15 days ago
Moderate
GSA_kwCzR0hTQS1mZjg1LXF3M2gtZzl2cM4ABOi-
Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 15 days ago
Moderate
GSA_kwCzR0hTQS14cGc4LTh4cHYtOTQ4cM4ABOi_
Mattermost does not enforce MFA on WebSocket connections
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 15 days ago
Low
GSA_kwCzR0hTQS1tcWNqLThjMmctaDk3cc4ABOhn
Mattermost Incorrect Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost-server/v6, github.com/mattermost/mattermost-server/v5, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Source: github
Published: 16 days ago
Low
GSA_kwCzR0hTQS14cjN3LXJtdmotZjZtN84ABNeq
Mattermost has an Observable Timing Discrepancy vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Source: github
Published: about 1 month ago
Moderate
GSA_kwCzR0hTQS03Y3IzLTM4am0tNnA0Nc4ABNex
Mattermost has a Missing Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Source: github
Published: about 1 month ago
Low
GSA_kwCzR0hTQS00MjRoLXhqODctbTkzN84ABNe8
Mattermost has an Incorrect Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Source: github
Published: about 1 month ago
High
GSA_kwCzR0hTQS1yNnFqLTg5NGYtNWhyMs4ABNe1
Mattermost has a Missing Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Source: github
Published: about 1 month ago
High
GSA_kwCzR0hTQS02cTdtLXA4Y2MtOTk4cs4ABNe_
Mattermost has a Missing Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Source: github
Published: about 1 month ago
Moderate
GSA_kwCzR0hTQS0zcTRxLXdxbTYtaHZmM84ABNe5
Mattermost has a Missing Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Source: github
Published: about 1 month ago
High
GSA_kwCzR0hTQS1xeDNmLTZ2cTMtOGo4bc4ABMZt
Mattermost Path Traversal vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 2 months ago
Low
GSA_kwCzR0hTQS1obTk1LWp4NjYtZzJnaM4ABMER
Mattermost Open Redirect vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Source: github
Published: 2 months ago
High
GSA_kwCzR0hTQS02OWo4LXByeDItdng5OM4ABMEQ
Mattermost Open Redirect vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 2 months ago
Moderate
GSA_kwCzR0hTQS05cDkyLXg3N3ctOWZ3Ms4ABMEa
Mattermost makes Use of Weak Hash
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 2 months ago
Moderate
GSA_kwCzR0hTQS0zdmNtLWM0MnAtM2hoZs4ABMEP
Mattermost Missing Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Source: github
Published: 2 months ago
Moderate
GSA_kwCzR0hTQS1wajZmLXJjOTQtZ3c1M84ABLUh
Mattermost Fails to Sanitize File Names
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 3 months ago
Moderate
GSA_kwCzR0hTQS1oNDY5LTRmY2YtcDIzaM4ABLUR
Mattermost has Potential Server Crash due to Unvalidated Import Data
Ecosystems: go
Packages: github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Source: github
Published: 3 months ago
Moderate
GSA_kwCzR0hTQS14NjdjLXY4anItcDI5cs4ABLTm
Mattermost Fails to Sanitize Path Traversal Sequences
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 3 months ago
Moderate
GSA_kwCzR0hTQS1xNDUzLTYzOGMtaDRtcs4ABLTn
Mattermost Fails to Validate Remote Cluster Upload Sessions
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 3 months ago
Low
GSA_kwCzR0hTQS12cXdoLTVqaGgtdmM5cM4ABLTk
Mattermost Server SSRF Vulnerability via the Agents Plugin
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 3 months ago
Low
GSA_kwCzR0hTQS1wd3ZyLWdycWctN3ZwMs4ABLTo
Mattermost Lack of Access Control Validation
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 3 months ago
Low
GSA_kwCzR0hTQS00Mjc2LWNtOGMtNzg4aM4ABLTj
Mattermost Fails to Properly Validate Team Role Modification
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 3 months ago
Moderate
GSA_kwCzR0hTQS1xajQ3LXc5ZjItcWc0NM4ABLTl
Mattermost Does Not Sanitize the Team Invite ID
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 3 months ago
Moderate
GSA_kwCzR0hTQS13dncyLTNqaDQtNGMzOc4ABKRq
Mattermost Path Traversal vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 4 months ago
Low
GSA_kwCzR0hTQS00ZndqLTg1OTUtd3AyNc4ABKRo
Mattermost has Insufficiently Protected Credentials
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 4 months ago
Moderate
GSA_kwCzR0hTQS03aDM0LTljaHItNThxaM4ABKRa
Mattermost Missing Authentication for Critical Function
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 4 months ago
Moderate
GSA_kwCzR0hTQS12OGZyLXZ4bXctNm1mNs4ABJkm
Mattermost Incorrect Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 5 months ago
Moderate
GSA_kwCzR0hTQS13Z3ZwLWpqNHctODhoZs4ABJkw
Mattermost Incorrect Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 5 months ago
Moderate
GSA_kwCzR0hTQS1xd3dtLWM1ODItODJyeM4ABJTJ
Mattermost allows unauthorized channel member management through playbook runs
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 5 months ago
Moderate
GSA_kwCzR0hTQS00NTc4LTZnamgtZjJqbc4ABJTD
Mattermost allows an unauthorized Guest user access to Playbook
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 5 months ago
Critical
GSA_kwCzR0hTQS1xaDU4LTl2M2otd2NqY84ABJSQ
Mattermost allows authenticated users to write files to arbitrary locations
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 5 months ago
Moderate
GSA_kwCzR0hTQS00cjY3LTR4NHAtZnByZ84ABI-v
Mattermost allows authenticated administrator to execute LDAP search filter injection
Ecosystems: go
Packages: github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Source: github
Published: 6 months ago
Low
GSA_kwCzR0hTQS1qd2h3LXhmNXYtcWd4Y84ABI-z
Mattermost allows guest users to view information about public teams they are not members of
Ecosystems: go
Packages: github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Source: github
Published: 6 months ago
Moderate
GSA_kwCzR0hTQS04Y2d4LTljY2otM2d3cs4ABIhX
Mattermost fails to clear Google OAuth credentials
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 6 months ago
Low
GSA_kwCzR0hTQS04NmpnLTM1eGotM3Z2Nc4ABIhZ
Mattermost fails to properly enforce access control restrictions for System Manager roles
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 6 months ago
Moderate
GSA_kwCzR0hTQS1tYzJmLWpnajYtNmNwM84ABIhc
Mattermost fails to properly invalidate personal access tokens upon user deactivation
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 6 months ago
Low
GSA_kwCzR0hTQS1oYzZ2LTM4Nm0tOTNwcc4ABIhV
Mattermost fails to properly enforce access controls for guest users
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 6 months ago
Moderate
GSA_kwCzR0hTQS00bW1yLTJ3OHAtd2hjcs4ABIfl
Mattermost improperly allows team administrators to modify team invites
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 6 months ago
Low
GSA_kwCzR0hTQS1mcGZmLXdqNm0tZ3J2cs4ABH5T
Mattermost Fails to Check User Access to `ExperimentalSettings`
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS1oMzU2LTNtZncteDM2OM4ABH5P
Mattermost Fails to Verify User's Permissions When Accessing Groups
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS1yN3IyLW0zdnItYzhxY84ABH4U
Mattermost Fails to Validate Team Invite Permissions
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS1xZ3d4LXJmZnAtNmN4Oc4ABH4T
Mattermost Fails to Lockout LDAP Users After Repeated Login Failures
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS02ODljLXhxN3gteGp3Zs4ABHIK
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions
Ecosystems: go
Packages: github.com/mattermost/mattermost-plugin-playbooks, github.com/mattermost/mattermost/server/v8
Source: github
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS0zZzM2LWdmN2MtNzVxd84ABHIQ
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
Ecosystems: go
Packages: github.com/mattermost/mattermost-plugin-playbooks, github.com/mattermost/mattermost/server/v8
Source: github
Published: 7 months ago
Low
GSA_kwCzR0hTQS1mcjIyLTUzNzctZjNwN84ABHIO
Mattermost Playbooks fails to properly validate permissions
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-playbooks
Source: github
Published: 7 months ago
Moderate
GSA_kwCzR0hTQS1tajJwLXYyYzItdmg0ds4ABG5Q
Mattermost Incorrect Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Moderate
GSA_kwCzR0hTQS0yajg3LXA2MjMtOGNjMs4ABG1v
Mattermost vulnerable to Observable Timing Discrepancy
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-msteams
Source: github
Published: 8 months ago
Low
GSA_kwCzR0hTQS05aDZqLTRmZngtY204NM4ABG1t
Mattermost doesn't restrict domains LLM can request to contact upstream
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Low
GSA_kwCzR0hTQS1qNWp3LW0ycGgtM2pqZs4ABG1k
Mattermost Missing Authentication for Critical Function
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Moderate
GSA_kwCzR0hTQS1oNHJyLWYzN2otNGhoN84ABG1q
Mattermost Incorrect Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Low
GSA_kwCzR0hTQS1qNjM5LW0zNjctNzVjZs4ABG1o
Mattermost Incorrect Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Low
GSA_kwCzR0hTQS13d2hqLXB3NmgtZjhod84ABGv_
Mattermost Incorrect Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Moderate
GSA_kwCzR0hTQS02cnFoLTg0NjUtMnhjd84ABGv3
Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Moderate
GSA_kwCzR0hTQS0zMjJ2LXZoMmctcXZwds4ABGvR
Mattermost Fails to Restrict Certain Operations on System Admins
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 8 months ago
Low
GSA_kwCzR0hTQS14ZnE5LWhoNXgteGZxOc4ABGsA
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Low
GSA_kwCzR0hTQS1jdzdxLTVjZ2MtaDNoOc4ABFw_
Mattermost fail to prompt for explicit approval before adding a team admin to a private channel
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Moderate
GSA_kwCzR0hTQS0zZ3B4LXA2M3AtcHI1cs4ABFxB
Mattermost Fails to Enforce Certain Search APIs
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Moderate
GSA_kwCzR0hTQS1oNXY5LXh3MmctN2hycc4ABFxA
Mattermost allows members with permission to convert public channels to private and convert private to public
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Source: github
Published: 8 months ago
High
GSA_kwCzR0hTQS03MnF2LWo4dnIteHZmds4ABFw7
Mattermost Fails to Enforce MFA on Plugin Endpoints
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Moderate
GSA_kwCzR0hTQS00djY1LXhxY2otd3BnZ84ABFw6
Mattermost Fails to Restrict Command Execution in Archived Channels
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Moderate
GSA_kwCzR0hTQS1ycDc0LXg0M20tY3B3M84ABFw-
Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Moderate
GSA_kwCzR0hTQS1mcXJxLXhteGotdjQ3eM4ABFpb
Mattermost Fails to Properly Perform Viewer Role Authorization
Ecosystems: go
Packages: github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Source: github
Published: 8 months ago
Moderate
GSA_kwCzR0hTQS1xOHAyLTJod2Mtanc2NM4ABEuF
Mattermost fails to restrict channel export of archived channels
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 9 months ago
Critical
GSA_kwCzR0hTQS01Znd4LXA2eGgtdmpyaM4ABEuE
Mattermost allows reading arbitrary files related to importing boards
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 9 months ago
Low
GSA_kwCzR0hTQS1yaHZyLTZ3OGMtNnY3d84ABEuC
Mattermost fails to invalidate all active sessions when converting a user to a bot
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 9 months ago
Critical
GSA_kwCzR0hTQS12NDY5LTd3cDYtN2N2cM4ABEuB
Mattermost allows reading arbitrary files
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 9 months ago
Moderate
GSA_kwCzR0hTQS13NnhoLWM4MnctaDk5N84ABDca
Mattermost webapp crash via a crafted post
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 11 months ago
Moderate
GSA_kwCzR0hTQS01bTdqLTZnYzQtZmY1Z84ABDah
Mattermost fails to properly validate post props
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 11 months ago
Moderate
GSA_kwCzR0hTQS00NXY5LXc5ZmgtMzNqNs4ABDao
Mattermost fails to properly validate post props
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 11 months ago
Moderate
GSA_kwCzR0hTQS04ajNxLWdjOXgtNzk3Ms4ABDZg
Mattermost Incorrect Type Conversion or Cast
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 11 months ago
Low
GSA_kwCzR0hTQS03cmdwLTRqNTYtZm03Oc4ABDHn
Mattermost has Improper Check for Unusual or Exceptional Conditions
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 11 months ago
Low
GSA_kwCzR0hTQS1xOGZnLWNwM3EtNWp3bc4ABDHt
Mattermost Incorrect Authorization vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 11 months ago
Moderate
GSA_kwCzR0hTQS0yNTQ5LXhoNzItcXJwbc4ABDHr
Mattermost Improper Validation of Specified Type of Input vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 11 months ago
Moderate
GSA_kwCzR0hTQS02OXByLTc4Z3YtN2M2aM4ABCdn
Mattermost Improper Validation of Specified Type of Input vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 12 months ago
Moderate
GSA_kwCzR0hTQS04MjZoLXA0YzMtNDc3cM4ABCdm
Mattermost Race Condition vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 12 months ago
Moderate
GSA_kwCzR0hTQS12NjQ3LWg4amotZnc1cs4ABCdp
Mattermost Data Amplification vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: 12 months ago
Moderate
GSA_kwCzR0hTQS02bXZwLWdoNzctN3Z3aM4ABAwn
Mattermost Server allows user to get private channel names
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS03NjJnLTlwN2YtbXJ3d84ABAwp
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS1nMzc2LW0zaDMtbWo0cs4ABAwy
Mattermost server allows authenticated user to delete arbitrary post
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS03NjJ2LXJxN3EtZmY5N84ABAw6
Mattermost Server vulnerable to application crash from attacker-generated large response
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: about 1 year ago
Low
GSA_kwCzR0hTQS1obTU3LWgyN3gtNTk5Y84ABAtz
Mattermost incorrectly issues two sessions when using desktop SSO
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS01OWhmLW1wZjgtcHFqaM4AA_yl
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: about 1 year ago
High
GSA_kwCzR0hTQS1meHE5LTY5NDYtMzRxN84AA-4r
Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS0yamh4LXczdmMtdzU5Z84AA-4u
Mattermost allows guest user with read access to upload files to a channel
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS0zajk1LThnNDctZnB3aM4AA-4h
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS01MjYzLXBtMmgtbTdod84AA-4C
Mattermost doesn't restrict which roles can promote a user as system admin
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS00d3c4LWZwcnEtY3EzNM4AA-4H
Mattermost doesn't redact remote users' original email addresses
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS1ocmY5LXJtOTUtZnBmM84AA-4D
Mattermost Cross-Site Request Forgery vulnerability
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS1jNnZwLWpqZ3YtMzh3as4AA-4J
Mattermost allows remote/synthetic users to create sessions, reset passwords
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
Critical
GSA_kwCzR0hTQS1xMjJxLTJycmYtbTI3cM4AA-UU
Mattermost allows unsolicited invites to expose access to local channels
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS05ZnB3LWM5eDctY3Yzas4AA-Ua
Mattermost allows remote actor to set arbitrary RemoteId values for synced users
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
High
GSA_kwCzR0hTQS12ZzY3LWNobTctOG0zas4AA-UZ
Mattermost allows remote actor to create/update/delete posts in arbitrary channels
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS03NjJtLTRjeDYtNm1mNM4AA-UV
Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS12ZzZxLTg0cDgtcXZxaM4AA-UW
Mattermost allows a user on a remote to set their remote username prop to an arbitrary string
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
Low
GSA_kwCzR0hTQS12dnBnLTU1cDctNWg4d84AA-UY
Mattermost did not properly restrict channel creation
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS1qcjl4LTN4N20tNGo3Nc4AA-UT
Mattermost allows a remote actor to make an arbitrary local channel read-only
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago
Moderate
GSA_kwCzR0hTQS1qcTNnLXhxcHgtMzd4M84AA-UR
Mattermost failed to properly validate synced reactions
Ecosystems: go
Packages: github.com/mattermost/mattermost/server/v8
Source: github
Published: over 1 year ago