Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-p267-jjfq-pphf: Mattermost fails to check if user is a guest before performing actions on public playbooks

Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.

ghsa
#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2023-4106

Mattermost fails to check if user is a guest before performing actions on public playbooks

Moderate severity GitHub Reviewed Published Aug 11, 2023 to the GitHub Advisory Database • Updated Aug 11, 2023

Package

gomod github.com/mattermost/mattermost-server/v6 (Go)

Affected versions

>= 7.9.0, <= 7.9.5

>= 7.10.0, <= 7.10.3

<= 7.8.7

Patched versions

7.9.6

7.10.4

7.8.8

Published to the GitHub Advisory Database

Aug 11, 2023

Last updated

Aug 11, 2023

ghsa: Latest News

GHSA-7p9f-6x8j-gxxp: CRI-O: Maliciously structured checkpoint file can gain arbitrary node access