VendorsMattermostmattermost_server9.3.0
Vulnerabilities

Mattermost Server 9.3.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-23493
Team associated AD/LDAP Groups Leaked due to missing authorization
Published 2024-02-29 · Analyzed
6.5EPSS 0.004
CVE-2024-1953
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, allowing an authenticated attacker to cause the server to run out of memory and crash by issuing an unusually large HTTP request.
Published 2024-02-29 · Analyzed
4.3EPSS 0.005
CVE-2024-1942
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an authenticated attacker to access the contents of individual posts in channels they are not a member of.
Published 2024-02-29 · Analyzed
4.3EPSS 0.004