Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qh58-9v3j-wcjc

Опубликовано: 20 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 9.9

Описание

Mattermost allows authenticated users to write files to arbitrary locations

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal sequences in filenames, potentially leading to remote code execution. The vulnerability impacts instances where file uploads and document search by content is enabled (FileSettings.EnableFileAttachments = true and FileSettings.ExtractContent = true). These configuration settings are enabled by default.

Пакеты

Наименование

github.com/mattermost/mattermost-server

go
Затронутые версииВерсия исправления

< 0.0.0-20250519205859-65aec10162f6

0.0.0-20250519205859-65aec10162f6

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

< 8.0.0-20250519205859-65aec10162f6

8.0.0-20250519205859-65aec10162f6

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 10.5.0, <= 10.5.5

10.5.6

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 9.11.0, <= 9.11.15

9.11.16

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

= 10.8.0

10.8.1

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 10.7.0, <= 10.7.2

10.7.3

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 10.6.0, <= 10.6.5

10.6.6

EPSS

Процентиль: 50%
0.00264
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 9.9
nvd
около 2 месяцев назад

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal sequences in filenames, potentially leading to remote code execution. The vulnerability impacts instances where file uploads and document search by content is enabled (FileSettings.EnableFileAttachments = true and FileSettings.ExtractContent = true). These configuration settings are enabled by default.

CVSS3: 9.9
debian
около 2 месяцев назад

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10. ...

EPSS

Процентиль: 50%
0.00264
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-427