CVE-2024-34152
26.05.2024, 14:15
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allows a guest toget the metadata of a public playbook run that linked to the channel they are guest via sending an RHSRuns GraphQL query request to the serverEnginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration