Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://mattermost.com/security-updates |
History
No history.
MITRE
Status: PUBLISHED
Assigner: Mattermost
Published: 2024-02-29T08:02:32.128Z
Updated: 2024-08-01T23:06:24.717Z
Reserved: 2024-02-26T08:14:42.964Z
Link: CVE-2024-23493
Vulnrichment
Updated: 2024-08-01T23:06:24.717Z
NVD
Status : Awaiting Analysis
Published: 2024-02-29T08:15:47.380
Modified: 2024-11-21T08:57:49.490
Link: CVE-2024-23493
Redhat
No data.