Loading HuntDB...

Misuse of groups feature allows workspace members to join private channels without being invited

High
S
Slack
Submitted None

Team Summary

Official summary from Slack

@kmap alerted us to an issue that would have allowed workspace members to join private channels through misuse of our User Groups feature. The bug was fixed on the next day, and Slack notified the few customers with users matching the conditions in the report. Many thanks to @kmap for reporting this!

Reported by kmap

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic