CVE-2023-27265

LOW

Mattermost - Info Disclosure

Title source: llm

Description

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

Scores

CVSS v3 2.7
EPSS 0.0025
EPSS Percentile 47.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200 CWE-668
Status published

Affected Products (1)

mattermost/mattermost_server < 7.7.0

Timeline

Published Feb 27, 2023
Tracked Since Feb 18, 2026