Security Advisory

CVE-2022-1003

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-03-18 18:00:21
Last updated 2024-12-06 23:10:28
Assigner Mattermost
State PUBLISHED

Description

One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.