Team members could access sensitive information of other users via an API call
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.8%
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
nono source reports it
Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
Mattermost · MattermostReferences
https://mattermost.com/security-updates/