Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/mattermost/mattermost/server/v8: GHSA-q8p2-2hwc-jw64 #3481

Open
GoVulnBot opened this issue Feb 24, 2025 · 0 comments

Comments

@GoVulnBot
Copy link

Advisory GHSA-q8p2-2hwc-jw64 references a vulnerability in the following Go modules:

Module
github.com/mattermost/mattermost-server
github.com/mattermost/mattermost-server/v5
github.com/mattermost/mattermost-server/v6
github.com/mattermost/mattermost/server/v8

Description:
Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when the "Allow users to view archived channels" is disabled which allows a user to export channel contents when they shouldn't have access to it

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/mattermost/mattermost-server
      versions:
        - introduced: 9.11.0-rc1+incompatible
        - fixed: 9.11.8+incompatible
        - introduced: 10.2.0-rc1+incompatible
        - fixed: 10.2.3+incompatible
        - introduced: 10.3.0-rc1+incompatible
        - fixed: 10.3.3+incompatible
        - introduced: 10.4.0-rc1+incompatible
        - fixed: 10.4.2+incompatible
      vulnerable_at: 10.4.1+incompatible
    - module: github.com/mattermost/mattermost-server/v5
      vulnerable_at: 5.39.3
    - module: github.com/mattermost/mattermost-server/v6
      vulnerable_at: 6.7.2
    - module: github.com/mattermost/mattermost/server/v8
      non_go_versions:
        - fixed: 8.0.0-20250110161910-96195f1bd746
      vulnerable_at: 8.0.0-20250224185354-1803f1c215e6
summary: Mattermost fails to restrict channel export of archived channels in github.com/mattermost/mattermost-server
cves:
    - CVE-2025-24526
ghsas:
    - GHSA-q8p2-2hwc-jw64
references:
    - advisory: https://github.com/advisories/GHSA-q8p2-2hwc-jw64
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-24526
    - fix: https://github.com/mattermost/mattermost-plugin-channel-export/commit/3c052b66207fb734bfc4c948941e7f7522a82550
    - fix: https://github.com/mattermost/mattermost/commit/96195f1bd7467f572525c35b5087acaeb53daa63
    - report: https://github.com/mattermost/mattermost-plugin-channel-export/issues/51
    - web: https://mattermost.com/security-updates
source:
    id: GHSA-q8p2-2hwc-jw64
    created: 2025-02-24T19:05:05.424759225Z
review_status: UNREVIEWED

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant