Mattermost incorrectly allows access individual posts
Low severity
GitHub Reviewed
Published
Feb 29, 2024
to the GitHub Advisory Database
•
Updated Sep 6, 2024
Package
Affected versions
>= 9.0.0, < 9.4.0
Patched versions
9.4.0
Description
Published by the National Vulnerability Database
Feb 29, 2024
Published to the GitHub Advisory Database
Feb 29, 2024
Reviewed
Feb 29, 2024
Last updated
Sep 6, 2024
Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member of.
References