Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.7, <= 10.7.0
- >= 10.5, <= 10.5.3
- >= 9.11, <= 9.11.12
A vulnerability exists in Mattermost versions 10.7.x through 10.7.0, 10.5.x through 10.5.3, and 9.11.x through 9.11.12. These versions fail to properly enforce access controls for guest users accessing channel member information. This allows authenticated guest users to view metadata about members of public channels through the channel members API endpoint.
Exploitation of this vulnerability allows authenticated guest users to access channel member metadata in public channels, bypassing intended access controls.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.