Vulnerability CVE-2022-2408


Published: 2022-07-14

Description:
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

 References:
https://mattermost.com/security-updates/

Copyright 2024, cxsecurity.com

 

Back to Top