An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.
| Software | From | Fixed in |
|---|---|---|
| mattermost / mattermost_server | 5.2.0-rc2 | 5.2.0-rc2.x |
| mattermost / mattermost_server | 5.2.0-rc3 | 5.2.0-rc3.x |
| mattermost / mattermost_server | 5.2.0-rc4 | 5.2.0-rc4.x |
| mattermost / mattermost_server | 5.2.0-rc5 | 5.2.0-rc5.x |
| mattermost / mattermost_server | 5.2.0-rc6 | 5.2.0-rc6.x |
| mattermost / mattermost_server | 5.2.0-rc1 | 5.2.0-rc1.x |
| mattermost / mattermost_server | - | 5.1.1 |