VDB
Sign up
MEDIUM4.3

GHSA-hwjf-4667-gqwx

Mattermost allows attackers access to posts in channels they are not a member of

Quick fix

GHSA-hwjf-4667-gqwx — github.com/mattermost/mattermost/server/v8: upgrade to the fixed version with the command below.

go get github.com/mattermost/mattermost/server/v8@v9.3.1

Details

Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an authenticated attacker to access the contents of individual posts in channels they are not a member of.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/mattermost/mattermost/server/v8
Introduced in: 9.3.0Fixed in: 9.3.1
Fixgo get github.com/mattermost/mattermost/server/v8@v9.3.1
Go/github.com/mattermost/mattermost/server/v8
Introduced in: 9.2.0Fixed in: 9.2.5
Fixgo get github.com/mattermost/mattermost/server/v8@v9.2.5
Go/github.com/mattermost/mattermost/server/v8
Introduced in: 0Fixed in: 8.1.9
Fixgo get github.com/mattermost/mattermost/server/v8@v8.1.9

References