Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membership privileges and perform actions restricted to playbook admins.
2022-05-03T21:15:08.773
2024-11-21T06:40:56.833
Modified
CVSSv3.1: 3.7 (LOW)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | playbooks | ≤ 1.25.0 | Yes |