Description
Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts
Problem types
CWE-863: Incorrect Authorization
Product status
10.5.0
10.10.0
10.5.9
Credits
Juho Forsén
References
mattermost.com/security-updates