CVE-2022-1332 – github.com/mattermost/mattermost-server/v6
Package
Manager: go
Name: github.com/mattermost/mattermost-server/v6
Vulnerable Version: >=6.4.0 <6.4.2 || >=6.3.0 <6.3.5 || >=6.0.0 <6.2.5
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L
EPSS: 0.00129 pctl0.33139
Details
Improper Privilege Management in Mattermost One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents. Per the Mattermost security updates page, versions 6.4.2, 6.3.5, 6.2.5, and 5.37.9 contain patches for this issue
Metadata
Created: 2022-04-14T00:00:17Z
Modified: 2022-04-22T21:05:51Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-qggc-pj29-j27m/GHSA-qggc-pj29-j27m.json
CWE IDs: ["CWE-200", "CWE-269"]
Alternative ID: GHSA-qggc-pj29-j27m
Finding: F159
Auto approve: 1