PT-2022-10681 · Mattermost · Mattermost

Published

2022-01-18

·

Updated

2022-10-27

·

CVE-2021-37864

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 6.1 and earlier
Description The issue arises from insufficient permission validation when viewing archived channels. This allows authenticated users to bypass system administrator restrictions and view the contents of archived channels by directly accessing the APIs.
Recommendations For Mattermost versions 6.1 and earlier, consider restricting access to archived channels until a fix is available, or apply specific configuration changes to enforce the intended permission settings.

Fix

Improper Access Control

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-37864

Affected Products

Mattermost