Mattermost是美国Mattermost公司的一个开源协作平台。 Mattermost iOS存在安全漏洞,该漏洞源于在初始化TLS连接时无法正确验证服务器证书,从而允许攻击者拦截WebSockets连接。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost iOS app | 0 ~ 2.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-3581 | 6.2 MEDIUM | WebSockets accept connections from HTTPS origin |
| CVE-2023-3591 | 4.8 MEDIUM | Lack of previous password reset tokens on new token creation |
| CVE-2023-3582 | 4.3 MEDIUM | Lack of channel membership check when linking a board to a channel |
| CVE-2023-3585 | 4.3 MEDIUM | channel DoS by sharing a boards link |
| CVE-2023-3614 | 4.3 MEDIUM | Denial of Service via specially crafted gif image |
| CVE-2023-3593 | 4.3 MEDIUM | Server crash via a specially crafted markdown input |
| CVE-2023-3586 | 4.2 MEDIUM | Disabling publicly-shared boards does not disable existing publicly available board links |
| CVE-2023-3577 | 3.5 LOW | Limited blind SSRF to localhost/intranet in interactive dialog implementation |
| CVE-2023-3613 | 3.5 LOW | Guest accounts invited and added to channels by Welcomebot plugin |
| CVE-2023-3584 | 3.1 LOW | Member can create team with team override scheme |
| CVE-2023-3590 | 3.1 LOW | Deleted attachments in Boards remain accessible |
| CVE-2023-3587 | 2.7 LOW | Inconsistent state in UI after boards permission change by system admin |
No comments yet