Описание
Mattermost Improper Access Control vulnerability
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users
endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.
Пакеты
github.com/mattermost/mattermost/server/v8
>= 9.1.0, < 9.1.1
9.1.1
github.com/mattermost/mattermost/server/v8
>= 9.0.0, < 9.0.2
9.0.2
github.com/mattermost/mattermost/server/v8
< 8.1.4
8.1.4
github.com/mattermost/mattermost-server/v6
< 7.8.13
7.8.13
Связанные уязвимости
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.
Mattermost fails to perform proper authorization in the /plugins/focal ...