Impact
Mattermost versions 11.3.0, 11.2.0–11.2.2 and 10.11.0–10.11.10 fail to use consistent error responses when processing the /mute slash command. This flaw allows an authenticated team member to distinguish between channels that do not exist and channels that are private and inaccessible, thereby enumerating the existence of private channels. The weakness is an information disclosure flaw (CWE‑203).
Affected Systems
The vulnerability affects Mattermost server deployments running any version 11.3.x that is less than or equal to 11.3.0, any 11.2.x version up to 11.2.2 inclusive, or any 10.11.x version up to 10.11.10 inclusive; newer releases such as 11.4.0, 11.3.1, 11.2.3, and 10.11.11 are not affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is below 1 %, suggesting a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user in the same Mattermost team and releases differing error messages depending on channel existence, so the attack vector is internal. No remote or unauthenticated exploitation is described.
OpenCVE Enrichment
Github GHSA