Security Advisory
CVE-2023-2787
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message threads API.