Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 11.2, <= 11.2.2
- >= 10.11, <= 10.11.10
- >= 11.4, <= 11.4.0
- >= 11.3, <= 11.3.1
A vulnerability exists in Mattermost versions 11.2.x through 11.2.2, 10.11.x through 10.11.10, 11.4.x through 11.4.0, and 11.3.x through 11.3.1. These versions fail to properly restrict view permissions when accessing group member IDs, allowing authenticated guest users to enumerate user IDs beyond their permitted visibility range via the group retrieval endpoint.
Exploitation of this vulnerability could lead to unauthorized enumeration of user IDs, potentially allowing guest users to gain insights into group member compositions that should remain private.
Users can upgrade to Mattermost versions 11.5.0 or 11.6.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.