PT-2022-13846 · Mattermost · Mattermost

Mr_Anksec

+1

·

Published

2022-04-19

·

Updated

2024-08-21

·

CVE-2022-1385

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 6.4.x and earlier
Description The issue arises from the failure to properly invalidate pending email invitations when the action is performed from the system console. This allows accidentally invited users to join the workspace and access information from public teams and channels. The problem is related to improper control of a resource through its lifetime in Mattermost.
Recommendations For Mattermost versions 6.4.x and earlier, consider restricting access to public teams and channels until a proper fix is applied to prevent accidentally invited users from accessing sensitive information. As a temporary workaround, manually invalidate pending email invitations to prevent unauthorized access.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2022-1385
CVE-2022-1385
GHSA-FXWJ-V664-WV5G
GO-2022-0599

Affected Products

Mattermost