Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of.
2024-02-29T08:15:47.380
2025-01-10T15:34:43.287
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_server | < 8.1.9 | Yes |
Application | mattermost | mattermost_server | < 9.2.5 | Yes |
Application | mattermost | mattermost_server | < 9.4.2 | Yes |
Application | mattermost | mattermost_server | 9.3.0 | Yes |
Application | mattermost | mattermost_server | 9.3.0 | Yes |
Application | mattermost | mattermost_server | 9.3.0 | Yes |