Bug 2056761 (CVE-2022-0708)

Summary: CVE-2022-0708 mattermost: API sensitive data exposure
Product: [Other] Security Response Reporter: Avinash Hanwate <ahanwate>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: amuller, anpicker, aos-bugs, bmontgom, eparis, erooth, extras-orphan, gparvin, jburrell, jokerman, jramanat, njean, nstielau, pahickey, spasquie, sponnaga, stcannon
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: mattermost 6.3.1, mattermost 6.2.2, mattermost 6.1.2, mattermost 5.37.7 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-03-25 19:45:11 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2056762, 2056763    
Bug Blocks: 2056764    

Description Avinash Hanwate 2022-02-22 03:54:36 UTC
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

https://mattermost.com/security-updates/

Comment 1 Avinash Hanwate 2022-02-22 03:55:05 UTC
Created purple-mattermost tracking bugs for this issue:

Affects: epel-all [bug 2056762]
Affects: fedora-all [bug 2056763]

Comment 2 Nick Tait 2022-03-25 16:47:33 UTC
Mattermost identifies this flaw as MMSA-2022-0082, but does not directly reference the CVE from their security update page.

Comment 3 Product Security DevOps Team 2022-03-25 19:45:08 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-0708