Description
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to version v6.4 or higher
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-24353 | One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates/ |
|
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:10:28.943Z
Reserved: 2022-03-17T00:00:00.000Z
Link: CVE-2022-1003
Updated: 2024-08-02T23:47:43.283Z
Status : Modified
Published: 2022-03-18T18:15:12.127
Modified: 2024-11-21T06:39:50.273
Link: CVE-2022-1003
No data.
OpenCVE Enrichment
No data.
EUVD