Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mattermost_server | Mattermost | 9.5.0 (including) | 9.5.9 (excluding) |