CVE-2022-2401Sensitive Information Exposure in Mattermost Mattermost-server V6

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 44.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateAug 21

Description

Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDmattermost/mattermost_server6.4.06.5.2+4
CVEListV5mattermost/mattermost6.x6.3.8+3

🔴Vulnerability Details

4
OSV
Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server2024-08-21
GHSA
Mattermost users could access some sensitive information via API call2022-07-15
OSV
Mattermost users could access some sensitive information via API call2022-07-15
CVEList
Team members could access sensitive information of other users via an API call2022-07-14
CVE-2022-2401 — Sensitive Information Exposure | cvebase