GHSA-qggc-pj29-j27m
Dashboard / Vulnerabilities / GHSA-qggc-pj29-j27m
GHSA-qggc-pj29-j27m
Summary: Improper Privilege Management in Mattermost
Details: One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents. Per the Mattermost security updates page, versions 6.4.2, 6.3.5, 6.2.5, and 5.37.9 contain patches for this issue
References: https://nvd.nist.gov/vuln/detail/CVE-2022-1332, https://github.com/mattermost/mattermost-server, https://mattermost.com/security-updates
Affected packages
Package
Name: github.com/mattermost/mattermost-server/v6
Purl: pkg:golang/github.com/mattermost/mattermost-server/v6
Affected ranges
Type: SEMVER
Events:
