Security Advisory
CVE-2023-49874
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID.