Mattermost fails to properly enforce access controls for guest users
Low severity
GitHub Reviewed
Published
May 30, 2025
to the GitHub Advisory Database
•
Updated May 30, 2025
Package
Affected versions
>= 10.6.0-rc1, < 10.7.1
>= 10.0.0-rc1, < 10.5.4
>= 9.0.0-rc1, < 9.11.13
< 8.0.0-20250414110750-c23f44fe8ed0
Patched versions
10.7.1
10.5.4
9.11.13
8.0.0-20250414110750-c23f44fe8ed0
Description
Published by the National Vulnerability Database
May 30, 2025
Published to the GitHub Advisory Database
May 30, 2025
Reviewed
May 30, 2025
Last updated
May 30, 2025
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.
References