Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mattermost_server | Mattermost | * | 7.8.14 (including) |
Mattermost_server | Mattermost | 8.0.0 (including) | 8.1.5 (including) |
Mattermost_server | Mattermost | 9.0.0 (including) | 9.0.3 (including) |
Mattermost_server | Mattermost | 9.1.1 (including) | 9.1.2 (including) |
Mattermost_server | Mattermost | 9.2.0 (including) | 9.2.1 (including) |