An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for setting a channel header) via the Channel header slash command API.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-21257.json"