CVE: CVE-2022-0708

Export to Word

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

Threat-Mapped Scoring

Score: 2.3

Priority: P3 - Important (Medium)

EPSS

Score: 0.0039
Percentile: 0.59249

CVSS Scoring

CVSS v3.1 Score: 4.3

Severity: MEDIUM

Mapped CWE(s)

All CAPEC(s)

CAPEC(s) with Mapped TTPs

Mapped ATT&CK TTPs

Malware

APTs Threat Group Associations

Campaigns

Affected Products

← Back to Home