An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "4.10.8"
},
{
"introduced": "5.7.0"
},
{
"fixed": "5.7.3"
},
{
"introduced": "5.8.0"
},
{
"fixed": "5.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "5.9.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "5.9.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "5.9.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "5.9.0-rc4"
}
]
}