Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users
endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.
{ "nvd_published_at": "2023-11-27T10:15:08Z", "cwe_ids": [ "CWE-284" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-11-28T20:53:16Z" }