Restricted custom admin role can bypass the restrictions and view the server logs and server config.json file contents
Published Apr 13, 2022
4.3
MEDIUMCVSS 3.1
EPSS 0.65%
Description
One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.
Affected products
-
Affected
- ≥ 5.37, < 5.37.9
- ≥ 6.2, < 6.2.5
- ≥ 6.3, < 6.3.5
- ≥ 6.4, < 6.4.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Mattermost | Mattermost | unknown | Affected
|
- ≥ 5.37.0 · < 5.37.9
- ≥ 6.2.0 · < 6.2.5
- ≥ 6.3.0 · < 6.3.5
- ≥ 6.4.0 · < 6.4.2
No data.
No Red Hat product state for this CVE.
github.com/mattermost/mattermost-server/v6
Go
Introduced 6.4.0 Fixed 6.4.2github.com/mattermost/mattermost-server/v6
Go
Introduced 6.3.0 Fixed 6.3.5github.com/mattermost/mattermost-server/v6
Go
Introduced 6.0.0 Fixed 6.2.5github.com/mattermost/mattermost-server/v5
Go
Introduced 0 Fixed 5.37.9github.com/mattermost/mattermost-server
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/mattermost/mattermost-server/v6 | 6.4.0 | 6.4.2 |
| Go | github.com/mattermost/mattermost-server/v6 | 6.3.0 | 6.3.5 |
| Go | github.com/mattermost/mattermost-server/v6 | 6.0.0 | 6.2.5 |
| Go | github.com/mattermost/mattermost-server/v5 | 0 | 5.37.9 |
| Go | github.com/mattermost/mattermost-server | 0 | not fixed |
Remediation
Vendor solution
Update Mattermost to version v6.4.2, 6.3.5, 6.2.5, or 5.37.9, depending on the minor version being run
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1816 Advisory
- https://github.com/advisories/GHSA-qggc-pj29-j27m Advisory
- https://mattermost.com/security-updates/ x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1332
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1816 | Advisory | |
| https://github.com/advisories/GHSA-qggc-pj29-j27m | Advisory | |
| https://mattermost.com/security-updates/ | x_refsource_MISCVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-1332 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub