MEDIUM
Guest accounts can list all public channels
Published Jul 14, 2022
4.3
MEDIUMCVSS 3.1
EPSS 0.60%
Description
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.
Affected products
-
- Version 6.4.xStatusaffectedConstraints-
- Version 6.5.xStatusaffectedConstraints<=6.5.1
- Version 6.6.xStatusaffectedConstraints<=6.6.1
- Version 6.7.x 6.7.0StatusaffectedConstraints-
- Version unspecifiedStatusaffectedConstraints<=6.3.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Mattermost | Mattermost | n/a |
|
OR
- < 6.3.8
- ≥ 6.4.0 · ≤ 6.5.1
- 6.6.0
- 6.6.1
- 6.7.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update Mattermost to version v7.0.0, 6.7.1, 6.6.2, 6.5.2, 6.3.9 or higher.
References (1)
- https://mattermost.com/security-updates/ x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://mattermost.com/security-updates/ | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Jul 14, 2022
Updated Dec 6, 2024
Reserved Jul 14, 2022
Link CVE-2022-2408
CISA Vulnrichment
Updated Dec 6, 2024