Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2022-02-21T17:49:29

Updated: 2024-08-02T23:40:03.256Z

Reserved: 2022-02-21T00:00:00

Link: CVE-2022-0708

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-02-21T18:15:08.957

Modified: 2022-03-01T15:45:51.550

Link: CVE-2022-0708

cve-icon Redhat

Severity : Low

Publid Date: 2022-02-21T00:00:00Z

Links: CVE-2022-0708 - Bugzilla