First published: Thu Jul 14 2022(Updated: )
Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | <6.3.9 | |
Mattermost Mattermost Server | >=6.4.0<6.5.2 | |
Mattermost Mattermost Server | =6.6.0 | |
Mattermost Mattermost Server | =6.6.1 | |
Mattermost Mattermost Server | =6.7.0 |
Update Mattermost to version v7.0.0, 6.7.1, 6.6.2, 6.5.2, 6.3.9 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the unrestricted information disclosure in Mattermost is CVE-2022-2401.
The severity level of CVE-2022-2401 is medium with a score of 6.5.
Mattermost version 6.7.0 and earlier is affected by CVE-2022-2401.
Team members can access sensitive information through CVE-2022-2401 by directly accessing the APIs.
To fix the unrestricted information disclosure vulnerability in Mattermost, it is recommended to update to the latest version of Mattermost that includes the security patch.