CVE-2022-2401

MEDIUM6.5EPSS 0.33%

Mattermost users could access some sensitive information via API call

發布日:2022/7/15修改日:2024/8/21
也稱為:GHSA-7ggc-5r84-xf54BIT-mattermost-2022-2401GO-2022-0540

描述

Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.

受影響套件(5)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

參考連結(5)