Mattermost fails to check whether the  “Allow users to view archived channels”  setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if the “Allow users to view archived channels” setting is disabled. 
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Mattermost

Published: 2023-11-27T09:11:13.283Z

Updated: 2023-11-27T09:11:13.283Z

Reserved: 2023-11-22T11:37:35.971Z


Link: CVE-2023-43754

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-27T10:15:07.657

Modified: 2023-12-01T21:18:42.600


Link: CVE-2023-43754

JSON object: View

cve-icon Redhat Information

No data.