CVE-2022-0708
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.
Affected (1)
Products: Mattermost: Mattermost
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.3.0 |
References (2)
Timeline
No history available yet.