Total vulnerabilities in the database
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.
Software | From | Fixed in |
---|---|---|
mattermost / mattermost | 6.4.0 | 6.5.1.x |
mattermost / mattermost | - | 6.3.8 |
mattermost / mattermost | 6.6.1 | 6.6.1.x |
mattermost / mattermost | 6.6.0 | 6.6.0.x |
mattermost / mattermost | 6.7.0 | 6.7.0.x |