VDB
Sign up
LOW3.1

GHSA-wwhj-pw6h-f8hw

Mattermost Incorrect Authorization vulnerability

Quick fix

GHSA-wwhj-pw6h-f8hw — github.com/mattermost/mattermost/server/v8: upgrade to the fixed version with the command below.

go get github.com/mattermost/mattermost/server/v8@v10.5.2

Details

Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/mattermost/mattermost/server/v8
Introduced in: 10.5.0Fixed in: 10.5.2
Fixgo get github.com/mattermost/mattermost/server/v8@v10.5.2
Go/github.com/mattermost/mattermost/server/v8
Introduced in: 9.11.0Fixed in: 9.11.10
Fixgo get github.com/mattermost/mattermost/server/v8@v9.11.10
Go/github.com/mattermost/mattermost/server/v8
Introduced in: 0Fixed in: 8.0.0-20250213231113-68c11e9ecb71
Fixgo get github.com/mattermost/mattermost/server/v8@v8.0.0-20250213231113-68c11e9ecb71

References