CVE-2023-27266

EUVD-2023-31044
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams  API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.


ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.7 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
MattermostCNA
2.7 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
Affected Products (NVD)
VendorProductVersion
mattermostmattermost_server
5.12.0 ≤
𝑥
< 7.7.0
𝑥
= Vulnerable software versions