Misuse of groups feature allows workspace members to join private channels without being invited
High
S
Slack
Submitted None
Team Summary
Official summary from Slack
@kmap alerted us to an issue that would have allowed workspace members to join private channels through misuse of our User Groups feature. The bug was fixed on the next day, and Slack notified the few customers with users matching the conditions in the report. Many thanks to @kmap for reporting this!
Actions:
Reported by
kmap
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic