Skip to content

x/vulndb: potential Go vuln in github.com/mattermost/mattermost/server/v8: GHSA-322v-vh2g-qvpv #3609

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Open
GoVulnBot opened this issue Apr 14, 2025 · 1 comment
Labels

Comments

@GoVulnBot
Copy link

Advisory GHSA-322v-vh2g-qvpv references a vulnerability in the following Go modules:

Module
github.com/mattermost/mattermost-server
github.com/mattermost/mattermost-server/v5
github.com/mattermost/mattermost-server/v6
github.com/mattermost/mattermost/server/v8

Description:
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to perform unauthorized modifications to system administrators via improper permission validation.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/mattermost/mattermost-server
      versions:
        - introduced: 9.11.0+incompatible
        - fixed: 9.11.10+incompatible
        - introduced: 10.4.0+incompatible
        - fixed: 10.4.4+incompatible
        - introduced: 10.5.0+incompatible
        - fixed: 10.5.2+incompatible
      vulnerable_at: 10.5.1+incompatible
    - module: github.com/mattermost/mattermost-server/v5
      vulnerable_at: 5.39.3
    - module: github.com/mattermost/mattermost-server/v6
      vulnerable_at: 6.7.2
    - module: github.com/mattermost/mattermost/server/v8
      versions:
        - fixed: 8.0.0-20250227102013-aa4623a93199
summary: Mattermost Fails to Restrict Certain Operations on System Admins in github.com/mattermost/mattermost-server
cves:
    - CVE-2025-32093
ghsas:
    - GHSA-322v-vh2g-qvpv
references:
    - advisory: https://github.com/advisories/GHSA-322v-vh2g-qvpv
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-32093
    - fix: https://github.com/mattermost/mattermost/commit/aa4623a9319943d9f54383b22b55e7d06a324e20
    - web: https://mattermost.com/security-updates
notes:
    - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
source:
    id: GHSA-322v-vh2g-qvpv
    created: 2025-04-14T20:05:03.706393488Z
review_status: UNREVIEWED

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/665975 mentions this issue: data/reports: add 12 reports

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants