Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.1.8"
},
{
"introduced": "7.2.0"
},
{
"fixed": "7.7.4"
},
{
"introduced": "7.8.0"
},
{
"fixed": "7.8.3"
},
{
"introduced": "7.9.0"
},
{
"fixed": "7.9.2"
}
]
}