ZeroHour

CVE-2022-1332

CVSS 3.1
4.3 medium
EPSS
<1%p49
Published
()
Modified
Description

One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.

Vendors
mattermost
Products
mattermost server
Weakness
CWE-200, CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.