CVE-2022-1003

Source
https://cve.org/CVERecord?id=CVE-2022-1003
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1003.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-1003
Published
2022-03-18T18:00:21Z
Modified
2026-07-15T01:49:20.594190819Z
Severity
  • 3.3 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Sysadmin can override existing configs & bypass restrictions like EnableUploads
Details

One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1003.json",
    "cwe_ids": [
        "CWE-268"
    ],
    "cna_assigner": "Mattermost",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "6.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/mattermost/mattermost

Affected ranges

Type
GIT
Repo
https://github.com/mattermost/mattermost
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6.4.0"
        }
    ],
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*"
}

Affected versions

Other
cloud-2022-01-26-1
cloud-2022-01-27-1
v0.*
v0.5.0
v4.*
v4.10.0-rc1
v4.2.0-rc1
v4.3.0-rc1
v4.4.0-rc1
v4.5.0-rc1
v4.6.0-rc1
v4.6.0-rc2
v4.7.0-rc1
v4.8.0-rc1
v4.9.0-rc1
v5.*
v5.0.0-rc1
v5.1.0-rc1
v5.2.0-rc1
v5.2.0-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1003.json"