CVE-2024-23493

Publication date

2024-02-29 08:02:32

Family

Mattermost

State

PUBLISHED

Description

Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of.