CVE-2023-49874

Publication date

2023-12-12 08:17:53

Family

Mattermost

State

PUBLISHED

Description

Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID.