An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the team invite_id, which leads to unintended excessive invitation privileges.
{ "versions": [ { "introduced": "4.6.0" }, { "fixed": "4.6.3" }, { "introduced": "4.7.0" }, { "fixed": "4.7.4" }, { "introduced": "4.8.0" }, { "fixed": "4.8.1" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-21261.json"