Mattermost fails to properly check permissions when retrieving a post allowing forĀ a System Role with the permission to manage channels to read the posts of a DM conversation.
2023-09-29T10:15:10.687
2024-11-21T08:41:16.473
Modified
CVSSv3.1: 4.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost | < 7.8.10 | Yes |
Application | mattermost | mattermost | < 8.0.2 | Yes |
Application | mattermost | mattermost | < 8.1.1 | Yes |