4.1

CVSS3.1

CVE-2024-41162 - Malicious remote can make an arbitrary local channel read-only

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only.

📅 Published: Aug. 1, 2024, 2:05 p.m. 🔄 Last Modified: Sept. 4, 2024, 5:03 p.m.

5.5

CVSS3.1

CVE-2024-41144 - Malicious remote can create/update/delete arbitrary posts in arbitrary channels

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled,  which allows a malicious remote to create/update/delete arbitrary posts in arbitrary channels

📅 Published: Aug. 1, 2024, 2:05 p.m. 🔄 Last Modified: Sept. 4, 2024, 5:25 p.m.

4.3

CVSS3.1

CVE-2024-39839 - Remote username set to an arbitrary string by remote user

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the …

📅 Published: Aug. 1, 2024, 2:05 p.m. 🔄 Last Modified: Sept. 4, 2024, 5:34 p.m.

3.8

CVSS3.1

CVE-2024-39837 - Malicious remote can create arbitrary channels

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.

📅 Published: Aug. 1, 2024, 2:05 p.m. 🔄 Last Modified: Sept. 4, 2024, 5:38 p.m.

6.8

CVSS3.1

CVE-2024-39832 - Permanently local data deletion by malicious remote

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled.

📅 Published: Aug. 1, 2024, 2:05 p.m. 🔄 Last Modified: Aug. 23, 2024, 2:35 p.m.

8.7

CVSS3.1

CVE-2024-39777 - Malicious remote can invite itself to an arbitrary local channel

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local channel, and that local…

📅 Published: Aug. 1, 2024, 2:05 p.m. 🔄 Last Modified: Aug. 23, 2024, 2:36 p.m.

8.7

CVSS3.1

CVE-2024-39274 - Malicious remote can add users to arbitrary teams and channels

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the sync message is a shared channel, when shared channels are enabled, which allows a malicious remote to add users to arbitrary teams and channels

📅 Published: Aug. 1, 2024, 2:05 p.m. 🔄 Last Modified: Aug. 23, 2024, 2:39 p.m.

7.4

CVSS3.1

CVE-2024-36492 - Existing local user overwritten by malicious remote

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing users in shared channels. which allows a malicious remote to overwrite an existing local user.

📅 Published: Aug. 1, 2024, 2:05 p.m. 🔄 Last Modified: Aug. 23, 2024, 2:51 p.m.

2.7

CVSS3.1

CVE-2024-29977 - Malicious remote can create arbitrary reactions on arbitrary posts

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts

📅 Published: Aug. 1, 2024, 2:05 p.m. 🔄 Last Modified: Aug. 23, 2024, 2:52 p.m.

8.5

CVSS4.0

CVE-2024-7358 - Point B Ltd Getscreen Agent Installation getscreen.msi temp file

A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file getscreen.msi of the component Installation. The manipulation leads to creation of temporary file with insecure permis…

📅 Published: Aug. 1, 2024, 1:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8978 of 34,919
« previous page » next page
Filters