MEDIUM
Invitation Email is resent as a Reminder after invalidating pending email invites
Published Apr 19, 2022
4.6
MEDIUMCVSS 3.1
EPSS 0.84%
Description
Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<6.5.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mattermost | Mattermost | n/a |
|
- < 6.5.0
No data.
No Red Hat product state for this CVE.
github.com/mattermost/mattermost-server/v6
Go
Introduced 0 Fixed 6.5.0github.com/mattermost/mattermost-server
Go
Introduced 0 Fixed not fixedgithub.com/mattermost/mattermost-server/v5
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/mattermost/mattermost-server/v6 | 0 | 6.5.0 |
| Go | github.com/mattermost/mattermost-server | 0 | not fixed |
| Go | github.com/mattermost/mattermost-server/v5 | 0 | not fixed |
Remediation
Vendor solution
Update Mattermost to version v6.5 or higher
References (4)
- https://github.com/advisories/GHSA-fxwj-v664-wv5g Advisory
- https://hackerone.com/reports/1486820 x_refsource_MISCExploitThird Party Advisory
- https://mattermost.com/security-updates/ x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1385
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-fxwj-v664-wv5g | Advisory | |
| https://hackerone.com/reports/1486820 | x_refsource_MISCExploitThird Party Advisory | |
| https://mattermost.com/security-updates/ | x_refsource_MISCVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-1385 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Apr 19, 2022
Updated Dec 6, 2024
Reserved Apr 18, 2022
Link CVE-2022-1385
CISA Vulnrichment
GHSA-FXWJ-V664-WV5G Updated Dec 6, 2024