Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2022-07-12 14:15
Updated : 2024-02-28 19:29
NVD link : CVE-2022-2366
Mitre link : CVE-2022-2366
CVE.ORG link : CVE-2022-2366
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-276
Incorrect Default Permissions