You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public.
See doc/quickstart.md for instructions on how to triage this report.
id: GO-ID-PENDING
modules:
- module: github.com/mattermost/mattermost-server
versions:
- introduced: 10.3.0+incompatible
- fixed: 10.3.4+incompatible
- introduced: 10.4.0+incompatible
- fixed: 10.4.3+incompatible
vulnerable_at: 10.4.3-rc3+incompatible
- module: github.com/mattermost/mattermost-server/v5
vulnerable_at: 5.39.3
- module: github.com/mattermost/mattermost-server/v6
vulnerable_at: 6.7.2
- module: github.com/mattermost/mattermost/server/v8
versions:
- fixed: 8.0.0-20250218135018-e644e3c8e393
- module: github.com/mattermost/mattermost/server/v9
non_go_versions:
- introduced: 9.11.0
- fixed: 9.11.9
summary: |-
Mattermost allows members with permission to convert public channels to private
and convert private to public in github.com/mattermost/mattermost-server
cves:
- CVE-2025-27933
ghsas:
- GHSA-h5v9-xw2g-7hrq
references:
- advisory: https://github.com/advisories/GHSA-h5v9-xw2g-7hrq
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-27933
- web: https://mattermost.com/security-updates
notes:
- fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
- fix: 'github.com/mattermost/mattermost/server/v9: could not add vulnerable_at: no fix, but could not find latest version from proxy: unexpected end of JSON input'
source:
id: GHSA-h5v9-xw2g-7hrq
created: 2025-03-21T23:04:19.961610909Z
review_status: UNREVIEWED
The text was updated successfully, but these errors were encountered:
Advisory GHSA-h5v9-xw2g-7hrq references a vulnerability in the following Go modules:
Description:
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public.
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: