Описание
Mattermost viewing archived public channels permissions vulnerability
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams//channels/deleted endpoint.
Пакеты
github.com/mattermost/mattermost-server/v6
<= 7.8.9
7.8.10
github.com/mattermost/mattermost/server/v8
<= 8.1.0
8.1.1
Связанные уязвимости
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.
Mattermost fails to properly verify the permissions needed for viewing ...