VYPR
Moderate severityNVD Advisory· Published Jul 14, 2022· Updated Dec 6, 2024

Team members could access sensitive information of other users via an API call

CVE-2022-2401

Description

Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost-server/v6Go
< 6.3.96.3.9
github.com/mattermost/mattermost-server/v6Go
>= 6.4.0, < 6.5.26.5.2
github.com/mattermost/mattermost-server/v6Go
>= 6.6.0, < 6.6.26.6.2
github.com/mattermost/mattermost-server/v6Go
>= 6.7.0, < 6.7.16.7.1

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.