Mattermost vulnerability allows arbitrary post contents access via /playbook add slash command
CVE-2024-36241
3.1LOW
What is CVE-2024-36241?
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook add slash command
Affected Version(s)
Mattermost 9.5.0 <= 9.5.3
Mattermost 9.6.0 <= 9.6.1
Mattermost 8.1.0 <= 8.1.12