New vulnerability on the NVD: CVE-2018-21259

An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel.

Published at: June 19, 2020 at 01:15PM
View on website

New vulnerability on the NVD: CVE-2018-21260

An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent during certain user-management operations, violating user privacy.

Published at: June 19, 2020 at 01:15PM
View on website

New vulnerability on the NVD: CVE-2018-21261

An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the team invite_id, which leads to unintended excessive invitation privileges.

Published at: June 19, 2020 at 01:15PM
View on website