Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- < 11.0.0
- >= 11.0.0, <= 11.0.210.12
- >= 10.12.1, <= 10.12.110.11
- >= 10.11.4, <= 10.11.410.5
- >= 10.5.12, <= 10.5.12
A vulnerability exists in Mattermost versions prior to 11.0, where the application fails to properly enforce the setting that allows users to view archived channels. This oversight enables regular users to access content and files from archived channels through the 'Open in Channel' feature within followed threads.
Exploitation of this vulnerability allows unauthorized access to archived channel content and files, potentially leading to the disclosure of sensitive information.
Users can upgrade to Mattermost version 11.1.011.0.310.12.210.11.510.5.13 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.