Mattermost fails to validate team membership when a user...
Low severity
Unreviewed
Published
Dec 12, 2023
to the GitHub Advisory Database
•
Updated Dec 12, 2023
Description
Published by the National Vulnerability Database
Dec 12, 2023
Published to the GitHub Advisory Database
Dec 12, 2023
Last updated
Dec 12, 2023
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team.
References