CVE-2021-37864

LOW

Mattermost < 6.1 - Authenticated Improper Access Control via Archived Channel API

Title source: llm
STIX 2.1

Description

Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://mattermost.com/security-updates/

Scores

CVSS v3 2.6
EPSS 0.0018
EPSS Percentile 38.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-863
Status published
Products (1)
mattermost/mattermost < 6.1
Published Jan 18, 2022
Tracked Since Feb 18, 2026