CVE-2023-27266

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
27/02/2023
Last modified:
07/11/2023

Description

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner&amp;#39;s email address in the response.<br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* 5.12.0 (including) 7.7.0 (excluding)


References to Advisories, Solutions, and Tools