Team Creator's Email Address is disclosed to Team Members via one of the APIs
Published Feb 21, 2022
6.5
MEDIUMCVSS 3.1
EPSS 0.80%
Description
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=6.3.0
- Version 5.37.7StatusunaffectedConstraints<unspecified
- Version 6.1.2StatusunaffectedConstraints<unspecified
- Version 6.2.2StatusunaffectedConstraints<unspecified
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Mattermost | Mattermost | n/a |
|
- ≤ 6.3.0
No data.
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-grafana-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-docs-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-main-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-rhel8-operator
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-roxctl-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-scanner-db-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-scanner-rhel8
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-docs-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-main-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-rhel8-operator | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-roxctl-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-scanner-db-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-scanner-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-0708 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2056761 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15783 Advisory
- https://mattermost.com/security-updates/ x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0708
- https://www.cve.org/CVERecord?id=CVE-2022-0708
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0708 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2056761 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15783 | Advisory | |
| https://mattermost.com/security-updates/ | x_refsource_MISCVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0708 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-0708 |
Change history (0)
No recorded changes yet.