The Guest account feature in Mattermost version 6.7.0 and...
Moderate severity
Unreviewed
Published
Jul 15, 2022
to the GitHub Advisory Database
•
Updated Jun 30, 2023
Description
Published by the National Vulnerability Database
Jul 14, 2022
Published to the GitHub Advisory Database
Jul 15, 2022
Last updated
Jun 30, 2023
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.
References