Mattermost fails to perform correct authorization checks...
Low severity
Unreviewed
Published
Dec 12, 2023
to the GitHub Advisory Database
•
Updated Dec 12, 2023
Description
Published by the National Vulnerability Database
Dec 12, 2023
Published to the GitHub Advisory Database
Dec 12, 2023
Last updated
Dec 12, 2023
Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access to the playbook to create playbook actions. If the playbook action created is to post a message in a channel based on specific keywords in a post, some playbook information, like the name, can be leaked.
References