PT-2022-13845 · Mattermost · Mattermost

Rohitesh Gupta

·

Published

2022-04-19

·

Updated

2024-08-21

·

CVE-2022-1384

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mattermost versions 6.4.x and earlier
Description The issue is related to insecure plugin handling in Mattermost, where the software fails to properly check the plugin version when a plugin is installed from the Marketplace. This allows an authenticated and authorized user to install and exploit an old plugin version from the Marketplace, which might have known vulnerabilities.
Recommendations For Mattermost versions 6.4.x and earlier, as a temporary workaround, consider restricting access to the plugin installation feature from the Marketplace until a patch is available. Additionally, avoid installing plugins from the Marketplace until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2022-1384
CVE-2022-1384
GHSA-32RP-Q37P-JG6W
GO-2022-0576

Affected Products

Mattermost