An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://mattermost.com/security-updates/ | vendor advisory |