Security Advisory

CVE-2022-1332

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-04-13 17:06:03
Last updated 2024-12-06 23:09:44
Assigner Mattermost
State PUBLISHED

Description

One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.