
CVE-2024-48872 – Bypass of "Max failed attempts" restriction via race condition
https://notcve.org/view.php?id=CVE-2024-48872
16 Dec 2024 — Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which allows an attacker to bypass of "Max failed attempts" restriction and send a big number of login attempts before being blocked via simultaneously sending multiple login requests Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed ... • https://mattermost.com/security-updates • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVE-2024-12247 – Improper propagation of permission scheme updates across cluster nodes
https://notcve.org/view.php?id=CVE-2024-12247
05 Dec 2024 — Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated. • https://mattermost.com/security-updates • CWE-863: Incorrect Authorization •

CVE-2024-11599 – Domain Restriction Bypass on Registration
https://notcve.org/view.php?id=CVE-2024-11599
28 Nov 2024 — Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registration. Las versiones de Mattermost 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 no logran validar correctamente las direcciones de correo electrónico, lo que permite que un usuario no autenticado eluda las restricciones de dom... • https://mattermost.com/security-updates • CWE-754: Improper Check for Unusual or Exceptional Conditions •

CVE-2024-52032 – Private channel names leaking when Elasticsearch is enabled
https://notcve.org/view.php?id=CVE-2024-52032
09 Nov 2024 — Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to get private channels names of channels that they are not a member of, when Elasticsearch v8 was enabled. Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to get private channels names of channels that they ... • https://mattermost.com/security-updates • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2024-36250 – MFA Code Replay
https://notcve.org/view.php?id=CVE-2024-36250
09 Nov 2024 — Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds • https://mattermost.com/security-updates • CWE-303: Incorrect Implementation of Authentication Algorithm •

CVE-2024-42000 – Unauthorized Access to view channels' details
https://notcve.org/view.php?id=CVE-2024-42000
09 Nov 2024 — Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels which allows a User or System Manager, with "Read Groups" permission but with no access for channels to retrieve details about private channels that they were not a member of by sending a request to /api/v4/channels. Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/... • https://mattermost.com/security-updates • CWE-863: Incorrect Authorization •

CVE-2024-46872 – Client-Side Path Traversal Leading to CSRF in Playbooks
https://notcve.org/view.php?id=CVE-2024-46872
29 Oct 2024 — Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks Las versiones 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 de Mattermost no pueden desinfectar las entradas del usuario en el frontend que se utilizan para la redirección, lo que permite un path traversal del lado del cliente con un solo clic que conduce a C... • https://mattermost.com/security-updates • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2024-47401 – DoS via Amplified GraphQL Response in Playbooks
https://notcve.org/view.php?id=CVE-2024-47401
29 Oct 2024 — Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn could cause the application to crash by sending a specially crafted request to Playbooks. Las versiones 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 y 9.5.x <= 9.5.9 de Mattermost no evitan que se muestren mensajes de error detallados en Playbooks, lo que p... • https://mattermost.com/security-updates • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2024-50052 – Arbitrary post deletion via Playbooks /ignore-thread endpoint
https://notcve.org/view.php?id=CVE-2024-50052
29 Oct 2024 — Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post. Las versiones de Mattermost 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 no verifican que el origen del mensaje en una acción de integración coincida con los metadatos de la publicación original, lo que permite que un usuario autenticado elimine una pu... • https://mattermost.com/security-updates • CWE-862: Missing Authorization •

CVE-2024-10241 – Private channel names leaked with Ctrl+K when ElasticSearch is enabled
https://notcve.org/view.php?id=CVE-2024-10241
29 Oct 2024 — Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K. Las versiones 9.5.x <= 9.5.9 de Mattermost no pueden filtrar correctamente los datos del canal cuando ElasticSearch está habilitado, lo que permite que un usuario obtenga nombres de canales privados mediante cmd+K/ctrl+K. Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled whi... • https://mattermost.com/security-updates • CWE-284: Improper Access Control •