CVE-2022-2401
14.07.2022, 18:15
Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mattermost | mattermost_server | 𝑥 < 6.3.9 |
| mattermost | mattermost_server | 6.4.0 ≤ 𝑥 < 6.5.2 |
| mattermost | mattermost_server | 6.6.0 |
| mattermost | mattermost_server | 6.6.1 |
| mattermost | mattermost_server | 6.7.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mattermost | mattermost | 6.0 ≤ 𝑥 ≤ 6.3.8 | CNA |
| mattermost | mattermost | 6.5.0 ≤ 𝑥 ≤ 6.5.1 | CNA |
| mattermost | mattermost | 6.6.0 ≤ 𝑥 ≤ 6.6.1 | CNA |
Common Weakness Enumeration