← back
CVE-2022-2366

Incorrect defaults can cause attackers to bypass rate limitations

CVSS 5.6 MEDIUMEPSS 0.5%CWE-276
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.6EPSS 0.5%KEV nãoPoC Patch
Lifecycle
11 Jul 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products
Mattermost · Mattermost

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →