HIGH7.1
GHSA-7664-hcp7-f497
Mattermost Injection vulnerability
Quick fix
GHSA-7664-hcp7-f497 — github.com/mattermost/mattermost-server/v6: upgrade to the fixed version with the command below.
go get github.com/mattermost/mattermost-server/v6@v7.8.14Details
Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/mattermost/mattermost-server/v6
Introduced in:
0Fixed in: 7.8.14Fix
go get github.com/mattermost/mattermost-server/v6@v7.8.14Go/github.com/mattermost/mattermost/server/v8
Introduced in:
0Fixed in: 8.1.5Fix
go get github.com/mattermost/mattermost/server/v8@v8.1.5Go/github.com/mattermost/mattermost/server/v8
Introduced in:
9.0.0Fixed in: 9.0.3Fix
go get github.com/mattermost/mattermost/server/v8@v9.0.3Go/github.com/mattermost/mattermost/server
Introduced in:
9.1.0Fixed in: 9.1.2Fix
go get github.com/mattermost/mattermost/server@v9.1.2