Описание
Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Mattermost fails to check whether the "Allow users to view archived channels" setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if the "Allow users to view archived channels" setting is disabled.
Пакеты
github.com/mattermost/mattermost/server/v8
>= 9.1.0, < 9.1.1
9.1.1
github.com/mattermost/mattermost/server/v8
>= 9.0.0, < 9.0.2
9.0.2
github.com/mattermost/mattermost/server/v8
< 8.1.4
8.1.4
github.com/mattermost/mattermost-server/v6
< 7.8.13
7.8.13
Связанные уязвимости
Mattermost fails to check whether the “Allow users to view archived channels” setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if the “Allow users to view archived channels” setting is disabled.
Mattermost fails to check whether the \u201cAllow users to view archiv ...