4
CVSSv2

CVE-2022-1332

Published: 13/04/2022 Updated: 20/04/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

One of the API in Mattermost version 6.4.1 and previous versions fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mattermost mattermost server