You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
See doc/quickstart.md for instructions on how to triage this report.
id: GO-ID-PENDING
modules:
- module: github.com/mattermost/mattermost-server
vulnerable_at: 10.4.1+incompatible
- module: github.com/mattermost/mattermost-server/v2
- module: github.com/mattermost/mattermost-server/v4
- module: github.com/mattermost/mattermost-server/v5
vulnerable_at: 5.39.3
- module: github.com/mattermost/mattermost-server/v6
vulnerable_at: 6.7.2
- module: github.com/mattermost/mattermost/server/v8
versions:
- fixed: 8.0.0-20250102081831-64c566a8280b
- module: github.com/mattermost/mattermost/server/v10
non_go_versions:
- introduced: 10.0.0
- fixed: 10.3.0
summary: Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server
cves:
- CVE-2025-22445
ghsas:
- GHSA-7rgp-4j56-fm79
references:
- advisory: https://github.com/advisories/GHSA-7rgp-4j56-fm79
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-22445
- web: https://mattermost.com/security-updates
notes:
- fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
- fix: 'github.com/mattermost/mattermost/server/v10: could not add vulnerable_at: no fix, but could not find latest version from proxy: unexpected end of JSON input'
- fix: 'github.com/mattermost/mattermost-server/v2: could not add vulnerable_at: no fix, but could not find latest version from proxy: unexpected end of JSON input'
- fix: 'github.com/mattermost/mattermost-server/v4: could not add vulnerable_at: no fix, but could not find latest version from proxy: unexpected end of JSON input'
source:
id: GHSA-7rgp-4j56-fm79
created: 2025-01-09T19:04:57.845139462Z
review_status: UNREVIEWED
The text was updated successfully, but these errors were encountered:
Advisory GHSA-7rgp-4j56-fm79 references a vulnerability in the following Go modules:
Description:
Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: