Mattermost Server allows user to get private channel names
Moderate severity
GitHub Reviewed
Published
Oct 29, 2024
to the GitHub Advisory Database
•
Updated Oct 29, 2024
Package
Affected versions
< 8.0.0-20240813135334-8f3a13122f55
Patched versions
8.0.0-20240813135334-8f3a13122f55
Description
Published by the National Vulnerability Database
Oct 29, 2024
Published to the GitHub Advisory Database
Oct 29, 2024
Reviewed
Oct 29, 2024
Last updated
Oct 29, 2024
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
References