CVE-2022-2408 MEDIUM

CVE-2022-2408: Guest accounts can list all public channels

Vendor Mattermost
Product Mattermost
Weakness CWE-200 · Info exposure
Published July 14, 2022
Last update December 6, 2024

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

Key dates

02Disclosure timeline

July 14, 2022 CVE published
December 6, 2024 Record updated