Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0708

Опубликовано: 21 фев. 2022
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-docs-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-rhel8-operatorNot affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-roxctl-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-scanner-db-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-scanner-rhel8Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2056761mattermost: API sensitive data exposure

EPSS

Процентиль: 59%
0.0039
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 3 лет назад

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

CVSS3: 4.3
debian
больше 3 лет назад

Mattermost 6.3.0 and earlier fails to protect email addresses of the c ...

github
больше 3 лет назад

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

EPSS

Процентиль: 59%
0.0039
Низкий

4.3 Medium

CVSS3

Уязвимость CVE-2022-0708