CVE-2022-1385
Summary
| CVE | CVE-2022-1385 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-19 21:15:00 UTC |
| Updated | 2022-04-27 21:19:00 UTC |
| Description | Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels. |
Risk And Classification
Problem Types: CWE-668
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mattermost | Mattermost Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| HackerOne | MISC | hackerone.com | |
| Security Updates - Mattermost Open Source Collaboration Platform | MISC | mattermost.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Thanks to mr_anon (mr_anksec) for contributing to this improvement under the Mattermost responsible disclosure policy.
There are currently no legacy QID mappings associated with this CVE.