Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 9.11.0, <= 9.11.8
A vulnerability exists in Mattermost versions 9.11.x prior to 9.11.8, where the application fails to enforce proper access controls on the /api/v4/audits endpoint. This flaw allows users with delegated granular administration roles, who do not have access to Compliance Monitoring, to retrieve User Activity Logs.
Exploitation of this vulnerability could lead to unauthorized access to User Activity Logs by users with certain administrative roles.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.