Mattermost Mobile 1.23.1

CPE Details

Mattermost Mobile 1.23.1
1.23.1
2025-01-10
17h38 +00:00
2025-01-10
17h38 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:mattermost:mattermost_mobile:1.23.1:*:*:*:*:*:*:*

Informations

Vendor

mattermost

Product

mattermost_mobile

Version

1.23.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-45833 2024-09-16 06h41 +00:00 Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the password contains a special character..
6.5
Medium
CVE-2024-39767 2024-07-15 08h43 +00:00 Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.
6.5
Medium
CVE-2024-32945 2024-07-15 08h42 +00:00 Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
5.3
Medium
CVE-2024-3872 2024-04-16 09h05 +00:00 Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.
6.5
Medium
CVE-2024-24975 2024-03-15 09h07 +00:00 Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the syntax highlighter, allowing an attacker to send a very large code block and crash the mobile app.
6.5
Medium
CVE-2019-20852 2020-06-19 12h04 +00:00 An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content).
7.5
High
CVE-2019-20850 2020-06-19 11h34 +00:00 An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.
5.3
Medium
CVE-2019-20849 2020-06-19 11h33 +00:00 An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.
5.3
Medium
CVE-2019-20848 2020-06-19 11h32 +00:00 An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies.
7.5
High
CVE-2020-14451 2020-06-19 11h08 +00:00 An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local Storage to remain after a logout, aka MMSA-2020-0013.
7.5
High
CVE-2020-14449 2020-06-19 11h07 +00:00 An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to third-party servers, aka MMSA-2020-0018.
7.5
High