{"id":"CVE-2022-1384","aliases":["BIT-mattermost-2022-1384","GHSA-32rp-q37p-jg6w","GO-2022-0576"],"url":"https://o3.security/vulnerability/CVE-2022-1384","summary":"Authorized users are allowed to install old plugin versions from the Marketplace","details":"Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known vulnerabilities.","published":"2022-04-19T20:26:28Z","modified":"2026-07-15T01:49:10.487696498Z","cvss":{"score":4.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/mattermost/mattermost-server/v6","fixedVersion":"6.5.0"}],"fix":null,"references":[{"type":"WEB","url":"https://mattermost.com/security-updates/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1384.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1384"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:10.487696498Z"}}