VDB
Sign up
MEDIUM4.3

GHSA-jj46-9cgh-qmfx

Mattermost Improper Access Control vulnerability

Quick fix

GHSA-jj46-9cgh-qmfx — github.com/mattermost/mattermost/server/v8: upgrade to the fixed version with the command below.

go get github.com/mattermost/mattermost/server/v8@v8.1.4

Details

Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/mattermost/mattermost/server/v8
Introduced in: 0Fixed in: 8.1.4
Fixgo get github.com/mattermost/mattermost/server/v8@v8.1.4
Go/github.com/mattermost/mattermost-server/v6
Introduced in: 0Fixed in: 7.8.13
Fixgo get github.com/mattermost/mattermost-server/v6@v7.8.13

References