An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.
References
Link Resource
https://mattermost.com/security-updates/ Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-06-19T16:49:18

Updated: 2020-06-19T16:49:18

Reserved: 2020-06-19T00:00:00


Link: CVE-2018-21251

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-06-19T17:15:12.490

Modified: 2020-06-26T20:06:52.743


Link: CVE-2018-21251

JSON object: View

cve-icon Redhat Information

No data.

CWE