VYPR
Unrated severityNVD Advisory· Published Mar 18, 2022· Updated Dec 6, 2024

Sysadmin can override existing configs & bypass restrictions like EnableUploads

CVE-2022-1003

Description

One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.