MEDIUM4.3
GHSA-hwjf-4667-gqwx
Mattermost allows attackers access to posts in channels they are not a member of
Quick fix
GHSA-hwjf-4667-gqwx — github.com/mattermost/mattermost/server/v8: upgrade to the fixed version with the command below.
go get github.com/mattermost/mattermost/server/v8@v9.3.1Details
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an authenticated attacker to access the contents of individual posts in channels they are not a member of.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/mattermost/mattermost/server/v8
Introduced in:
9.3.0Fixed in: 9.3.1Fix
go get github.com/mattermost/mattermost/server/v8@v9.3.1Go/github.com/mattermost/mattermost/server/v8
Introduced in:
9.2.0Fixed in: 9.2.5Fix
go get github.com/mattermost/mattermost/server/v8@v9.2.5Go/github.com/mattermost/mattermost/server/v8
Introduced in:
0Fixed in: 8.1.9Fix
go get github.com/mattermost/mattermost/server/v8@v8.1.9