Team members could access sensitive information of other users via an API call
Published Jul 14, 2022
6.5
MEDIUMCVSS 3.1
EPSS 0.83%
Description
Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.
Affected products
-
- Version 6.5.xStatusaffectedConstraints<=6.5.1
- Version 6.6.xStatusaffectedConstraints<=6.6.1
- Version 6.7.x 6.7.0StatusaffectedConstraints-
- Version 6.xStatusaffectedConstraints<=6.3.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Mattermost | Mattermost | n/a |
|
- < 6.3.9
- ≥ 6.4.0 · < 6.5.2
- 6.6.0
- 6.6.1
- 6.7.0
No data.
No Red Hat product state for this CVE.
github.com/mattermost/mattermost-server/v6
Go
Introduced 6.4.0 Fixed 6.5.2github.com/mattermost/mattermost-server/v6
Go
Introduced 6.6.0 Fixed 6.6.2github.com/mattermost/mattermost-server/v6
Go
Introduced 6.7.0 Fixed 6.7.1github.com/mattermost/mattermost-server/v6
Go
Introduced 0 Fixed 6.3.9github.com/mattermost/mattermost-server
Go
Introduced 0 Fixed not fixedgithub.com/mattermost/mattermost-server/v5
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/mattermost/mattermost-server/v6 | 6.4.0 | 6.5.2 |
| Go | github.com/mattermost/mattermost-server/v6 | 6.6.0 | 6.6.2 |
| Go | github.com/mattermost/mattermost-server/v6 | 6.7.0 | 6.7.1 |
| Go | github.com/mattermost/mattermost-server/v6 | 0 | 6.3.9 |
| Go | github.com/mattermost/mattermost-server | 0 | not fixed |
| Go | github.com/mattermost/mattermost-server/v5 | 0 | not fixed |
Remediation
Vendor solution
Update Mattermost to version v7.0.0, 6.7.1, 6.6.2, 6.5.2, 6.3.9 or higher.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6283 Advisory
- https://github.com/advisories/GHSA-7ggc-5r84-xf54 Advisory
- https://mattermost.com/security-updates/ x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2401
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6283 | Advisory | |
| https://github.com/advisories/GHSA-7ggc-5r84-xf54 | Advisory | |
| https://mattermost.com/security-updates/ | x_refsource_MISCVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2401 |
Change history (0)
No recorded changes yet.