CVE-2021-37864
Published on: 01/18/2022 12:00:00 AM UTC
Last Modified on: 10/27/2022 11:44:00 AM UTC
Certain versions of Mattermost from Mattermost contain the following vulnerability:
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.
- CVE-2021-37864 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Mattermost - Mattermost version < 6.2
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Security Updates - Mattermost Open Source Collaboration Platform | mattermost.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Mattermost | Mattermost | All | All | All | All |
- cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-37864 : Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived chann… twitter.com/i/web/status/1… | 2022-01-18 17:16:01 |
![]() |
CVE-2021-37864 | 2022-01-18 17:39:03 |