Vulnerability Description
Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mattermost | Mattermost Server | < 6.5.0 |
Related Weaknesses (CWE)
References
- https://hackerone.com/reports/1486820ExploitThird Party Advisory
- https://mattermost.com/security-updates/Vendor Advisory
- https://hackerone.com/reports/1486820ExploitThird Party Advisory
- https://mattermost.com/security-updates/Vendor Advisory
FAQ
What is CVE-2022-1385?
CVE-2022-1385 is a vulnerability with a CVSS score of 3.7 (LOW). Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace ...
How severe is CVE-2022-1385?
CVE-2022-1385 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1385?
Check the references section above for vendor advisories and patch information. Affected products include: Mattermost Mattermost Server.