PT-2022-16456 · Mattermost · Mattermost
Rohit Kc
·
Published
2022-07-14
·
Updated
2023-06-30
·
CVE-2022-2408
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mattermost versions 6.7.0 and earlier
Description
The Guest account feature fails to properly restrict permissions, allowing a guest user to fetch a list of all public channels in the team, even if they are not part of those channels.
Recommendations
For Mattermost versions 6.7.0 and earlier, consider disabling the Guest account feature until a patch is available to properly restrict permissions and prevent unauthorized access to public channels.
Fix
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mattermost