Описание
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
Пакеты
github.com/mattermost/mattermost/server/v8
>= 9.5.0, < 9.5.8
9.5.8
github.com/mattermost/mattermost/server/v8
>= 9.10.0, < 9.10.1
9.10.1
Связанные уязвимости
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly ...