VDB
Sign up
HIGH7.1

GHSA-7664-hcp7-f497

Mattermost Injection vulnerability

Quick fix

GHSA-7664-hcp7-f497 — github.com/mattermost/mattermost-server/v6: upgrade to the fixed version with the command below.

go get github.com/mattermost/mattermost-server/v6@v7.8.14

Details

Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/mattermost/mattermost-server/v6
Introduced in: 0Fixed in: 7.8.14
Fixgo get github.com/mattermost/mattermost-server/v6@v7.8.14
Go/github.com/mattermost/mattermost/server/v8
Introduced in: 0Fixed in: 8.1.5
Fixgo get github.com/mattermost/mattermost/server/v8@v8.1.5
Go/github.com/mattermost/mattermost/server/v8
Introduced in: 9.0.0Fixed in: 9.0.3
Fixgo get github.com/mattermost/mattermost/server/v8@v9.0.3
Go/github.com/mattermost/mattermost/server
Introduced in: 9.1.0Fixed in: 9.1.2
Fixgo get github.com/mattermost/mattermost/server@v9.1.2

References