Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, which allows authenticated users to view members and member information of archived channels even when this setting is disabled.
{
"cwe_ids": [
"CWE-863"
],
"nvd_published_at": "2025-04-16T17:15:49Z",
"github_reviewed_at": "2025-04-16T19:44:28Z",
"severity": "MODERATE",
"github_reviewed": true
}