MEDIUM4.3
GHSA-w88v-pjr8-cmv2
Mattermost viewing archived public channels permissions vulnerability
Quick fix
GHSA-w88v-pjr8-cmv2 — github.com/mattermost/mattermost-server/v6: upgrade to the fixed version with the command below.
go get github.com/mattermost/mattermost-server/v6@v7.8.10Details
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/mattermost/mattermost-server/v6
Introduced in:
0Fixed in: 7.8.10Fix
go get github.com/mattermost/mattermost-server/v6@v7.8.10Go/github.com/mattermost/mattermost/server/v8
Introduced in:
0Fixed in: 8.1.1Fix
go get github.com/mattermost/mattermost/server/v8@v8.1.1