Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Mattermost
Published: 2022-02-21T17:49:29
Updated: 2022-02-21T17:49:29
Reserved: 2022-02-21T00:00:00
Link: CVE-2022-0708
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-02-21T18:15:08.957
Modified: 2022-03-01T15:45:51.550
Link: CVE-2022-0708
JSON object: View
Redhat Information
No data.
CWE