Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "8.1.9"
},
{
"introduced": "9.0.0"
},
{
"fixed": "9.2.5"
},
{
"introduced": "9.4.0"
},
{
"fixed": "9.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "9.3.0-rc2"
}
]
}