mautrix / discord

A Matrix-Discord puppeting bridge
https://go.mau.fi/mautrix-discord
GNU Affero General Public License v3.0
240 stars 22 forks source link

Permission escalation issue with multiple user using the same matrix server #112

Closed Marc-Pierre-Barbier closed 11 months ago

Marc-Pierre-Barbier commented 11 months ago

I have a discord server where I'm not an admin and I can only see a few channels. a friend of mine has access to some more channels.

We both use the same matrix server, and we both have our accounts linked using mautrix-discord.

In matrix, I can see the channels he should only be able to see.

Since I get access to information I should not have access to, this is privilege escalation.

tulir commented 11 months ago

Duplicate of #107