Back

MEDIUM

Restricted custom admin role can bypass the restrictions and view the server logs and server config.json file contents

Published Apr 13, 2022

Description

One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.

Affected products

Remediation

Vendor solution

Update Mattermost to version v6.4.2, 6.3.5, 6.2.5, or 5.37.9, depending on the minor version being run

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Mattermost
Published Apr 13, 2022
Updated Dec 6, 2024
Reserved Apr 13, 2022

CISA Vulnrichment

Updated Dec 6, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Mattermost
Published Apr 13, 2022
Updated Dec 6, 2024