|
209881
|
7.3 |
HIGH
Network
|
mattermost
|
mattermost_desktop
|
An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.
|
CWE-346
Origin Validation Error
|
CVE-2020-14456
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209882
|
6.5 |
MEDIUM
Network
|
mattermost
|
mattermost_desktop
|
An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-2020-0007.
|
CWE-287
Improper Authentication
|
CVE-2020-14455
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209883
|
6.1 |
MEDIUM
Network
|
mattermost
|
mattermost_desktop
|
An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008.
|
CWE-601
Open Redirect
|
CVE-2020-14454
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209884
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, which allows attackers to cause a denial of service, aka MMSA-2020-0005.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-14453
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209885
|
5.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-0014.
|
CWE-22
Path Traversal
|
CVE-2020-14452
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209886
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_mobile
|
An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local Storage to remain after a logout, aka MMSA-2020-0013.
|
CWE-459
Incomplete Cleanup
|
CVE-2020-14451
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209887
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 5.22.0. The markdown renderer allows attackers to cause a denial of service (client-side), aka MMSA-2020-0017.
|
NVD-CWE-noinfo
|
CVE-2020-14450
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209888
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_mobile
|
An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to third-party servers, aka MMSA-2020-0018.
|
NVD-CWE-noinfo
|
CVE-2020-14449
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209889
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0020.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-14448
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209890
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0021.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-14447
|
2024-11-21 14:03 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|