Back

MEDIUM

Team Creator's Email Address is disclosed to Team Members via one of the APIs

Published Feb 21, 2022

Description

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Feb 21, 2022
Updated Dec 6, 2024
Reserved Feb 21, 2022
CISA Vulnrichment
Updated Dec 6, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 21, 2022
ENISA EUVD
Assigner Mattermost
Published Feb 21, 2022
Updated Dec 6, 2024
Exploited since n/a
EUVD-2022-15783