First published: Tue Dec 12 2023(Updated: )
Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allowing an attacker to get limited information about a post if they know the post ID
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | <=7.8.14 | |
Mattermost Mattermost Server | >=8.0.0<=8.1.5 | |
Mattermost Mattermost Server | >=9.0.0<=9.0.3 | |
Mattermost Mattermost Server | >=9.1.1<=9.1.2 | |
Mattermost Mattermost Server | >=9.2.0<=9.2.1 |
Update Mattermost Server to versions 8.1.6, 9.0.4, 9.1.3, 9.2.2 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Inaccessible Post Information Leak via Run Timeline IDOR vulnerability in Mattermost.
It allows attackers to access limited information about a post if they know the post ID.
Ensure to apply the security updates provided by Mattermost.