An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permissions for configuration files.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "5.9.7"
},
{
"introduced": "5.15.0"
},
{
"fixed": "5.15.4"
},
{
"introduced": "5.16.0"
},
{
"fixed": "5.16.4"
},
{
"introduced": "5.17.0"
},
{
"fixed": "5.17.2"
},
{
"introduced": "0"
},
{
"last_affected": "5.18.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "5.18.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "5.18.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "5.18.0-rc4"
}
]
}