Mattermost是美国Mattermost公司的一个开源协作平台。 Mattermost存在安全漏洞,该漏洞源于无法验证外部网站上链接的安全性,导致攻击者可以通过在消息中链接到特制网页来造成拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost | 0 ~ 7.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-2792 | 6.5 MEDIUM | Ephemeral messages return private channel contents in permalink previews |
| CVE-2023-2787 | 6.5 MEDIUM | Collapsed Reply Threads APIs leak message contents from private channels |
| CVE-2023-2788 | 6.2 MEDIUM | Deactivated user can retain access using oauth2 api |
| CVE-2023-2785 | 4.3 MEDIUM | Specially crafted search query can cause large log entries in postgres |
| CVE-2023-2831 | 4.3 MEDIUM | Denial of Service while unescaping a Markdown string |
| CVE-2023-2791 | 4.3 MEDIUM | Playbooks lets you edit arbitrary posts |
| CVE-2023-2786 | 4.3 MEDIUM | Channel commands execution doesn't properly verify permissions |
| CVE-2023-2783 | 4.3 MEDIUM | App Framework does not checks for the secret provided in the incoming webhook request |
| CVE-2023-2784 | 4.2 MEDIUM | Apps Framework allows install requests from regular members via an internal path |
| CVE-2023-2797 | 3.1 LOW | Path traversal in GitHub plugin's code preview feature |
No comments yet