Описание
Mattermost fails to check if user is a guest before performing actions on public playbooks
Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.
Пакеты
github.com/mattermost/mattermost-server/v6
>= 7.9.0, <= 7.9.5
7.9.6
github.com/mattermost/mattermost-server/v6
>= 7.10.0, <= 7.10.3
7.10.4
github.com/mattermost/mattermost-server/v6
<= 7.8.7
7.8.8
Связанные уязвимости
Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.
Mattermost fails to check if the requesting user is a guest before per ...