Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 11.3, <= 11.3.0
- >= 11.2, <= 11.2.2
- >= 10.11, <= 10.11.10
A vulnerability exists in Mattermost versions 11.3.x prior to 11.3.0, 11.2.x prior to 11.2.2, and 10.11.x prior to 10.11.10. These versions do not properly enforce read permissions in search API endpoints, allowing guest users without read permissions to access posts and files in channels through search API requests.
Exploitation of this vulnerability allows unauthorized access to posts and files in channels via the search API, bypassing normal read permissions for guest users.
Users can upgrade to Mattermost versions 11.5.0, 11.4.0, or 10.11.12 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.