CVE-2022-2366

MEDIUM

Mattermost Server <= 6.7.0 - Incorrect Default Permissions via Trusted IP Header

Title source: llm
STIX 2.1

Description

Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://mattermost.com/security-updates/

Scores

CVSS v3 5.6
EPSS 0.0019
EPSS Percentile 40.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (2)
mattermost/mattermost_server 6.7.0
mattermost/mattermost_server < 6.3.9
Published Jul 12, 2022
Tracked Since Feb 18, 2026