Unrated severityNVD Advisory· Published Feb 21, 2022· Updated Dec 6, 2024
Team Creator's Email Address is disclosed to Team Members via one of the APIs
CVE-2022-0708
Description
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.
Affected products
1- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- mattermost.com/security-updates/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.