CVE-2023-27266
27.02.2023, 15:15
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.Enginsight
Vendor | Product | Version |
---|---|---|
mattermost | mattermost_server | 5.12.0 ≤ 𝑥 < 7.7.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration