Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID.
This Cyber News was published on www.tenable.com. Publication date: Tue, 12 Dec 2023 22:41:03 +0000