Total vulnerabilities in the database
Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.
Software | From | Fixed in |
---|---|---|
![]() |
7.9.0 | 7.9.6 |
![]() |
7.10.0 | 7.10.4 |
![]() |
- | 7.8.8 |
mattermost / mattermost | 7.10.0 | 7.10.4 |
mattermost / mattermost | 7.9.0 | 7.9.6 |
mattermost / mattermost | 7.8.0 | 7.8.8 |