Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.3 Go

Improper Privilege Management in Mattermost

GHSA-qggc-pj29-j27m · BIT-mattermost-2022-1332 · CVE-2022-1332 · GO-2022-0616

Published · Modified

Description

One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents. Per the Mattermost security updates page, versions 6.4.2, 6.3.5, 6.2.5, and 5.37.9 contain patches for this issue

Ready to move

Start Securing

Free, no credit card | First findings in minutes