-
Notifications
You must be signed in to change notification settings - Fork 67
x/vulndb: potential Go vuln in github.com/mattermost/mattermost/server/v8: GHSA-q8fg-cp3q-5jwm #3377
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Labels
Comments
Change https://go.dev/cl/641815 mentions this issue: |
This was referenced Jan 15, 2025
This was referenced Feb 24, 2025
This was referenced Mar 19, 2025
This was referenced Apr 11, 2025
# for free
to join this conversation on GitHub.
Already have an account?
# to comment
Advisory GHSA-q8fg-cp3q-5jwm references a vulnerability in the following Go modules:
Description:
Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: