Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.5, <= 10.5.4
- >= 9.11, <= 9.11.13
A vulnerability exists in Mattermost versions 10.5.x through 10.5.4 and 9.11.x through 9.11.13, allowing guest users to bypass permissions and access information about public teams they do not belong to. This issue arises from improper restrictions on API access to team data, enabling unauthorized visibility through direct calls to the teams API endpoint.
Exploitation of this vulnerability allows unauthorized access to team information, potentially leading to privacy violations by disclosing details about public teams that a user is not a member of.
Users can upgrade to Mattermost versions 10.9.0 or 10.8.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.