CVE-2022-2408: Guest accounts can list all public channels
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-2408?
CVE-2022-2408 is a vulnerability in Mattermost version 6.7.0 and earlier that allows a guest user to fetch a list of all public channels in the team, despite not being part of those channels.
What is the severity of CVE-2022-2408?
The severity of CVE-2022-2408 is medium with a CVSS score of 4.3.
How does CVE-2022-2408 affect Mattermost?
CVE-2022-2408 affects Mattermost version 6.7.0 and earlier by failing to properly restrict the permissions of the Guest account feature, allowing a guest user to fetch a list of all public channels.
Which versions of Mattermost are affected by CVE-2022-2408?
Mattermost version 6.7.0 and earlier are affected by CVE-2022-2408.
How can I fix CVE-2022-2408?
To fix CVE-2022-2408, it is recommended to upgrade to a version of Mattermost that is not affected by the vulnerability. Please refer to the vendor's security updates for more information.