Description
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook add slash command
Problem types
CWE-284: Improper Access Control
Product status
9.5.0 (semver)
9.6.0 (semver)
8.1.0 (semver)
9.7.0
9.5.4
9.6.2
8.1.13
Credits
Juho Nurminen
References
mattermost.com/security-updates