Mattermost Server 8.1.10

CPE Details

Mattermost Server 8.1.10
8.1.10
2025-01-10
14h38 +00:00
2025-01-10
14h38 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:mattermost:mattermost_server:8.1.10:-:*:*:*:*:*:*

Informations

Vendor

mattermost

Product

mattermost_server

Version

8.1.10

Update

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-4198 2024-04-26 08h26 +00:00 Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.
2.7
Low
CVE-2024-4195 2024-04-26 08h26 +00:00 Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guests to team admins via crafted HTTP requests.
2.7
Low
CVE-2024-4183 2024-04-26 08h25 +00:00 Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
6.5
Medium
CVE-2024-4182 2024-04-26 08h25 +00:00 Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
4.3
Medium
CVE-2024-32046 2024-04-26 08h24 +00:00 Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored
4.3
Medium
CVE-2024-22091 2024-04-26 08h24 +00:00 Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user inputs which allows an attacker to cause excessive resource consumption, possibly leading to a DoS via sending large request paths
6.5
Medium
CVE-2024-2447 2024-04-05 08h52 +00:00 Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.
6.5
Medium
CVE-2024-29221 2024-04-05 08h15 +00:00 Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the invite ID of their team, thus allowing them to invite users, even if the "Add Members" permission was explicitly removed from team admins.
4.7
Medium
CVE-2024-28949 2024-04-05 08h14 +00:00 Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.
6.5
Medium
CVE-2024-21848 2024-04-05 08h13 +00:00 Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel
3.1
Low