CVE-2022-1385 Vulnerability Details

  /     /     /  

CVE-2022-1385 Metadata Quick Info

CVE Published: 19/04/2022 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: Mattermost | Vendor: Mattermost | Product: Mattermost
Status : PUBLISHED

CVE-2022-1385 Description

Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels.

Metrics

CVSS Version: 3.1 | Base Score: 3.7 LOW
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* LOW
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* LOW
    Integrity Impact (I)* LOW
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-664
CWE Name: CWE-664 Improper Control of a Resource Through its Lifetime
Source: Mattermost

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).