CVE-2022-2366: Incorrect defaults can cause attackers to bypass rate limitations
Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2022-2366.
What is the severity of CVE-2022-2366?
The severity of CVE-2022-2366 is medium with a CVSS score of 5.3.
How does CVE-2022-2366 impact Mattermost?
CVE-2022-2366 allows an attacker to bypass rate limitations or manipulate IP addresses for audit logging in Mattermost versions 6.7.0 and earlier.
Which software versions are affected by CVE-2022-2366?
Mattermost versions 6.3.9, 6.4.0 to 6.5.2, 6.6.0 to 6.6.2, and 6.7.0 are affected by CVE-2022-2366.
How can I mitigate CVE-2022-2366?
To mitigate CVE-2022-2366, update to a version of Mattermost that is not affected by the vulnerability and follow the recommendations provided by Mattermost security updates.