-
Notifications
You must be signed in to change notification settings - Fork 67
x/vulndb: potential Go vuln in github.com/mattermost/mattermost/server/v8: GHSA-826h-p4c3-477p #3338
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Labels
Comments
Change https://go.dev/cl/636717 mentions this issue: |
This was referenced Jan 9, 2025
This was referenced Feb 24, 2025
This was referenced Mar 19, 2025
This was referenced Apr 11, 2025
This was referenced Apr 16, 2025
# for free
to join this conversation on GitHub.
Already have an account?
# to comment
Advisory GHSA-826h-p4c3-477p references a vulnerability in the following Go modules:
Description:
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which allows an attacker to bypass of "Max failed attempts" restriction and send a big number of login attempts before being blocked via simultaneously sending multiple login requests
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: