ZeroHour

CVE-2022-1003

CVSS 3.1
4.9 medium
EPSS
<1%p41
Published
()
Modified
Description

One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.

Vendors
mattermost
Products
mattermost
Weakness
CWE-268, CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.