GHSA-xgxj-j98c-59rv

Suggest an improvement
Source
https://github.com/advisories/GHSA-xgxj-j98c-59rv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-xgxj-j98c-59rv/GHSA-xgxj-j98c-59rv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xgxj-j98c-59rv
Aliases
Related
Published
2024-02-29T09:30:34Z
Modified
2024-07-15T22:00:20.894414Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Mattermost fails to properly restrict the access of files attached to posts
Details

Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members being able to access files of archived channels even if the “Allow users to view archived channels” option is disabled.

Database specific
{
    "nvd_published_at": "2024-02-29T08:15:47Z",
    "cwe_ids": [
        "CWE-284"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-29T22:48:21Z"
}
References

Affected packages

Go / github.com/mattermost/mattermost/server/v8

Package

Name
github.com/mattermost/mattermost/server/v8
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost/server/v8

Affected ranges

Type
SEMVER
Events
Introduced
9.0.0
Fixed
9.4.2

Go / github.com/mattermost/mattermost/server/v8

Package

Name
github.com/mattermost/mattermost/server/v8
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost/server/v8

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.1.9