Total vulnerabilities in the database
Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.
Software | From | Fixed in |
---|---|---|
![]() |
- | 8.1.8 |
![]() |
9.0.0 | 9.3.0 |
mattermost / mattermost_server | - | 8.1.7.x |