Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.
2024-07-03T09:15:07.210
2024-11-21T09:28:22.227
Modified
CVSSv3.1: 3.1 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost | < 9.5.6 | Yes |
Application | mattermost | mattermost | < 9.8.1 | Yes |