Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.
{
"github_reviewed_at": "2023-11-28T20:53:16Z",
"severity": "MODERATE",
"github_reviewed": true,
"cwe_ids": [
"CWE-284"
],
"nvd_published_at": "2023-11-27T10:15:08Z"
}