Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel
Solution:
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
Link | Tags |
---|---|
https://mattermost.com/security-updates | vendor advisory |