Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user edit permissions to manage/update bots.
2023-09-29T10:15:10.530
2024-11-21T08:41:12.140
Modified
CVSSv3.1: 3.8 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost | < 7.8.10 | Yes |
Application | mattermost | mattermost | < 8.1.1 | Yes |