Vulnerabilities
Vulnerable Software
Mattermost fails to properly verify the permissions needed for viewing archived public channels,  allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.
CVSS Score
4.3
EPSS Score
0.002
Published
2024-01-02
Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.
CVSS Score
4.3
EPSS Score
0.006
Published
2024-01-02
Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.
CVSS Score
3.7
EPSS Score
0.001
Published
2024-01-02
Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.
CVSS Score
3.7
EPSS Score
0.007
Published
2023-12-29


Contact Us

Shodan ® - All rights reserved