x/vulndb: potential Go vuln in github.com/mattermost/mattermost/server/v8: GHSA-fpff-wj6m-grvr · Issue #3694 · golang/vulndb · GitHub
More Web Proxy on the site http://driver.im/
You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 fail to check RestrictSystemAdmin setting if user doesn't have access to ExperimentalSettings which allows a System Manager to access ExperimentSettings when RestrictSystemAdmin is true via System Console.
Advisory GHSA-fpff-wj6m-grvr references a vulnerability in the following Go modules:
Description:
Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 fail to check
RestrictSystemAdmin
setting if user doesn't have access toExperimentalSettings
which allows a System Manager to accessExperimentSettings
whenRestrictSystemAdmin
is true via System Console.References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: