Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.
2023-08-11T07:15:09.853
2024-11-21T08:34:24.353
Modified
CVSSv3.1: 6.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost | < 7.8.8 | Yes |
Application | mattermost | mattermost | < 7.9.6 | Yes |
Application | mattermost | mattermost | < 7.10.4 | Yes |