CVE-2022-1548: Playbook members are allowed to escalate their membership privileges and perform actions restricted to playbook admins.
Published May 3, 2022
·Updated
Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membership privileges and perform actions restricted to playbook admins.
Affected Software
1 affected component
Mattermost Playbooks<=1.25.0
Remediation
Information
Update Mattermost Playbooks Plugin to version v1.26.0 or higher.
Event History
May 3, 2022
CVE Published
via MITRE·08:11 PM
Data Sourced
via MITRE·08:11 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1548?
The severity of CVE-2022-1548 is classified as medium due to the potential for privilege escalation.
2
How do I fix CVE-2022-1548?
To fix CVE-2022-1548, upgrade the Mattermost Playbooks plugin to version 1.26.0 or later.
3
Who is affected by CVE-2022-1548?
Users of Mattermost Playbooks plugin versions 1.25 and earlier are affected by CVE-2022-1548.
4
What actions can be escalated due to CVE-2022-1548?
CVE-2022-1548 allows playbook members to perform actions that are normally restricted to playbook admins.
5
Is there a workaround for CVE-2022-1548?
There are no documented workarounds for CVE-2022-1548; updating to the latest version is recommended.