Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
{
"cwe_ids": [
"CWE-284"
],
"github_reviewed": true,
"nvd_published_at": "2024-10-29T08:15:11Z",
"github_reviewed_at": "2024-10-29T16:06:28Z",
"severity": "MODERATE"
}