Status
Justification
Impact
This was fixed in mattermost/server v7.4.0. In the relevant hackerone page: https://hackerone.com/reports/1685979 Mattermost staff say this is fixed and released on 10/17/22. Referencing the mattermost security updates page: https://mattermost.com/security-updates/ MMSA-2022-00118 was added on 10/14/22 and thanked the user in hackerone page for "contributing to this improvement" and the descriptions of the issue is the same between the two sources.
Status