LOW3.1
GHSA-jcgv-3pfq-j4hr
Mattermost Injection vulnerability
Quick fix
GHSA-jcgv-3pfq-j4hr — github.com/mattermost/mattermost/server/v8: upgrade to the fixed version with the command below.
go get github.com/mattermost/mattermost/server/v8@v8.1.4Details
Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/mattermost/mattermost/server/v8
Introduced in:
0Fixed in: 8.1.4Fix
go get github.com/mattermost/mattermost/server/v8@v8.1.4Go/github.com/mattermost/mattermost-server/v6
Introduced in:
0Fixed in: 7.8.13Fix
go get github.com/mattermost/mattermost-server/v6@v7.8.13