CVE-2022-1385Improper Control of a Resource Through its Lifetime in Mattermost

Severity
4.6MEDIUMNVD
CNA3.7CISA7.8
EPSS
0.2%
top 61.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 19
Latest updateAug 21

Description

Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:NExploitability: 2.1 | Impact: 2.5

Affected Packages3 packages

🔴Vulnerability Details

4
OSV
Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server2024-08-21
GHSA
Improper Control of a Resource Through its Lifetime in Mattermost2022-04-20
OSV
Improper Control of a Resource Through its Lifetime in Mattermost2022-04-20
CVEList
Invitation Email is resent as a Reminder after invalidating pending email invites2022-04-19

📋Vendor Advisories

1
CISA
Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability2022-05-23
CVE-2022-1385 — Mattermost vulnerability | cvebase