Vulnerabilities > CVE-2022-1384 - Missing Authorization vulnerability in Mattermost Server

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
mattermost
CWE-862

Summary

Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known vulnerabilities.

Vulnerable Configurations

Part Description Count
Application
Mattermost
615

Common Weakness Enumeration (CWE)