PT-2022-13584 · Mattermost · Mattermost

Rohitesh Gupta

·

Published

2022-03-18

·

Updated

2022-03-29

·

CVE-2022-1003

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 6.3.0 and earlier
Description The issue concerns a problem with an API in Mattermost where system administrators can combine two distinct privileges to override certain restricted configurations, such as EnableUploads.
Recommendations For Mattermost versions 6.3.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1003

Affected Products

Mattermost