PT-2022-13845 · Mattermost · Mattermost
Rohitesh Gupta
·
Published
2022-04-19
·
Updated
2024-08-21
·
CVE-2022-1384
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mattermost versions 6.4.x and earlier
Description
The issue is related to insecure plugin handling in Mattermost, where the software fails to properly check the plugin version when a plugin is installed from the Marketplace. This allows an authenticated and authorized user to install and exploit an old plugin version from the Marketplace, which might have known vulnerabilities.
Recommendations
For Mattermost versions 6.4.x and earlier, as a temporary workaround, consider restricting access to the plugin installation feature from the Marketplace until a patch is available. Additionally, avoid installing plugins from the Marketplace until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mattermost