From 2936c57d79c9a01044aa9a47bed4a26e1d959231 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 30 May 2025 18:49:35 +0000 Subject: [PATCH] Publish Advisories GHSA-86jg-35xj-3vv5 GHSA-8cgx-9ccj-3gwr GHSA-hc6v-386m-93pq GHSA-mc2f-jgj6-6cp3 GHSA-86jg-35xj-3vv5 GHSA-8cgx-9ccj-3gwr GHSA-hc6v-386m-93pq GHSA-mc2f-jgj6-6cp3 --- .../GHSA-86jg-35xj-3vv5.json | 122 +++++++++++++++ .../GHSA-8cgx-9ccj-3gwr.json | 141 ++++++++++++++++++ .../GHSA-hc6v-386m-93pq.json | 122 +++++++++++++++ .../GHSA-mc2f-jgj6-6cp3.json | 141 ++++++++++++++++++ .../GHSA-86jg-35xj-3vv5.json | 36 ----- .../GHSA-8cgx-9ccj-3gwr.json | 36 ----- .../GHSA-hc6v-386m-93pq.json | 36 ----- .../GHSA-mc2f-jgj6-6cp3.json | 36 ----- 8 files changed, 526 insertions(+), 144 deletions(-) create mode 100644 advisories/github-reviewed/2025/05/GHSA-86jg-35xj-3vv5/GHSA-86jg-35xj-3vv5.json create mode 100644 advisories/github-reviewed/2025/05/GHSA-8cgx-9ccj-3gwr/GHSA-8cgx-9ccj-3gwr.json create mode 100644 advisories/github-reviewed/2025/05/GHSA-hc6v-386m-93pq/GHSA-hc6v-386m-93pq.json create mode 100644 advisories/github-reviewed/2025/05/GHSA-mc2f-jgj6-6cp3/GHSA-mc2f-jgj6-6cp3.json delete mode 100644 advisories/unreviewed/2025/05/GHSA-86jg-35xj-3vv5/GHSA-86jg-35xj-3vv5.json delete mode 100644 advisories/unreviewed/2025/05/GHSA-8cgx-9ccj-3gwr/GHSA-8cgx-9ccj-3gwr.json delete mode 100644 advisories/unreviewed/2025/05/GHSA-hc6v-386m-93pq/GHSA-hc6v-386m-93pq.json delete mode 100644 advisories/unreviewed/2025/05/GHSA-mc2f-jgj6-6cp3/GHSA-mc2f-jgj6-6cp3.json diff --git a/advisories/github-reviewed/2025/05/GHSA-86jg-35xj-3vv5/GHSA-86jg-35xj-3vv5.json b/advisories/github-reviewed/2025/05/GHSA-86jg-35xj-3vv5/GHSA-86jg-35xj-3vv5.json new file mode 100644 index 00000000000..4beade2db4c --- /dev/null +++ b/advisories/github-reviewed/2025/05/GHSA-86jg-35xj-3vv5/GHSA-86jg-35xj-3vv5.json @@ -0,0 +1,122 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86jg-35xj-3vv5", + "modified": "2025-05-30T18:48:32Z", + "published": "2025-05-30T15:30:32Z", + "aliases": [ + "CVE-2025-3611" + ], + "summary": "Mattermost fails to properly enforce access control restrictions for System Manager roles", + "details": "Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.6.0-rc1" + }, + { + "fixed": "10.7.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.0.0-rc1" + }, + { + "fixed": "10.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0-rc1" + }, + { + "fixed": "9.11.13" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "8.0.0-20250414154356-6f33b721de76" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3611" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/6f33b721de76b39a7714bfe0d5e9c1306869a3e3" + }, + { + "type": "PACKAGE", + "url": "https://github.com/mattermost/mattermost" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-05-30T18:48:31Z", + "nvd_published_at": "2025-05-30T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/05/GHSA-8cgx-9ccj-3gwr/GHSA-8cgx-9ccj-3gwr.json b/advisories/github-reviewed/2025/05/GHSA-8cgx-9ccj-3gwr/GHSA-8cgx-9ccj-3gwr.json new file mode 100644 index 00000000000..8b3c5a5b3fc --- /dev/null +++ b/advisories/github-reviewed/2025/05/GHSA-8cgx-9ccj-3gwr/GHSA-8cgx-9ccj-3gwr.json @@ -0,0 +1,141 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cgx-9ccj-3gwr", + "modified": "2025-05-30T18:48:23Z", + "published": "2025-05-30T15:30:32Z", + "aliases": [ + "CVE-2025-2571" + ], + "summary": "Mattermost fails to clear Google OAuth credentials", + "details": "Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.7.0-rc1" + }, + { + "fixed": "10.7.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.0.0-rc1" + }, + { + "fixed": "10.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0-rc1" + }, + { + "fixed": "9.11.13" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "8.0.0-20250414095146-04676582cdd2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.6.0-rc1" + }, + { + "fixed": "10.6.3" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2571" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/04676582cdd26f4fdfa78fcf60a7f8745e6b27f5" + }, + { + "type": "PACKAGE", + "url": "https://github.com/mattermost/mattermost" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-303" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-05-30T18:48:23Z", + "nvd_published_at": "2025-05-30T15:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/05/GHSA-hc6v-386m-93pq/GHSA-hc6v-386m-93pq.json b/advisories/github-reviewed/2025/05/GHSA-hc6v-386m-93pq/GHSA-hc6v-386m-93pq.json new file mode 100644 index 00000000000..ef6ea736015 --- /dev/null +++ b/advisories/github-reviewed/2025/05/GHSA-hc6v-386m-93pq/GHSA-hc6v-386m-93pq.json @@ -0,0 +1,122 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc6v-386m-93pq", + "modified": "2025-05-30T18:48:20Z", + "published": "2025-05-30T15:30:32Z", + "aliases": [ + "CVE-2025-1792" + ], + "summary": "Mattermost fails to properly enforce access controls for guest users", + "details": "Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.6.0-rc1" + }, + { + "fixed": "10.7.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.0.0-rc1" + }, + { + "fixed": "10.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0-rc1" + }, + { + "fixed": "9.11.13" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "8.0.0-20250414110750-c23f44fe8ed0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1792" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/c23f44fe8ed02f71d506f99adc30ad34c58c89d1" + }, + { + "type": "PACKAGE", + "url": "https://github.com/mattermost/mattermost" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-05-30T18:48:20Z", + "nvd_published_at": "2025-05-30T15:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/05/GHSA-mc2f-jgj6-6cp3/GHSA-mc2f-jgj6-6cp3.json b/advisories/github-reviewed/2025/05/GHSA-mc2f-jgj6-6cp3/GHSA-mc2f-jgj6-6cp3.json new file mode 100644 index 00000000000..41e9c4742f8 --- /dev/null +++ b/advisories/github-reviewed/2025/05/GHSA-mc2f-jgj6-6cp3/GHSA-mc2f-jgj6-6cp3.json @@ -0,0 +1,141 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc2f-jgj6-6cp3", + "modified": "2025-05-30T18:48:28Z", + "published": "2025-05-30T15:30:32Z", + "aliases": [ + "CVE-2025-3230" + ], + "summary": "Mattermost fails to properly invalidate personal access tokens upon user deactivation", + "details": "Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.7.0-rc1" + }, + { + "fixed": "10.7.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.6.0-rc1" + }, + { + "fixed": "10.6.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.0.0-rc1" + }, + { + "fixed": "10.5.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0-rc1" + }, + { + "fixed": "9.11.13" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "8.0.0-20250402193107-65343f84a783" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3230" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/65343f84a7830fa8078fe3df879fca924e4fac01" + }, + { + "type": "PACKAGE", + "url": "https://github.com/mattermost/mattermost" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-303" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-05-30T18:48:27Z", + "nvd_published_at": "2025-05-30T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-86jg-35xj-3vv5/GHSA-86jg-35xj-3vv5.json b/advisories/unreviewed/2025/05/GHSA-86jg-35xj-3vv5/GHSA-86jg-35xj-3vv5.json deleted file mode 100644 index 1e370a7db88..00000000000 --- a/advisories/unreviewed/2025/05/GHSA-86jg-35xj-3vv5/GHSA-86jg-35xj-3vv5.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-86jg-35xj-3vv5", - "modified": "2025-05-30T15:30:32Z", - "published": "2025-05-30T15:30:32Z", - "aliases": [ - "CVE-2025-3611" - ], - "details": "Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3611" - }, - { - "type": "WEB", - "url": "https://mattermost.com/security-updates" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-863" - ], - "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-05-30T15:15:41Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8cgx-9ccj-3gwr/GHSA-8cgx-9ccj-3gwr.json b/advisories/unreviewed/2025/05/GHSA-8cgx-9ccj-3gwr/GHSA-8cgx-9ccj-3gwr.json deleted file mode 100644 index a3dd331edef..00000000000 --- a/advisories/unreviewed/2025/05/GHSA-8cgx-9ccj-3gwr/GHSA-8cgx-9ccj-3gwr.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-8cgx-9ccj-3gwr", - "modified": "2025-05-30T15:30:32Z", - "published": "2025-05-30T15:30:32Z", - "aliases": [ - "CVE-2025-2571" - ], - "details": "Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2571" - }, - { - "type": "WEB", - "url": "https://mattermost.com/security-updates" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-303" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-05-30T15:15:40Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hc6v-386m-93pq/GHSA-hc6v-386m-93pq.json b/advisories/unreviewed/2025/05/GHSA-hc6v-386m-93pq/GHSA-hc6v-386m-93pq.json deleted file mode 100644 index 3cd50737f30..00000000000 --- a/advisories/unreviewed/2025/05/GHSA-hc6v-386m-93pq/GHSA-hc6v-386m-93pq.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-hc6v-386m-93pq", - "modified": "2025-05-30T15:30:32Z", - "published": "2025-05-30T15:30:32Z", - "aliases": [ - "CVE-2025-1792" - ], - "details": "Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1792" - }, - { - "type": "WEB", - "url": "https://mattermost.com/security-updates" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-863" - ], - "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-05-30T15:15:40Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mc2f-jgj6-6cp3/GHSA-mc2f-jgj6-6cp3.json b/advisories/unreviewed/2025/05/GHSA-mc2f-jgj6-6cp3/GHSA-mc2f-jgj6-6cp3.json deleted file mode 100644 index fec3a281703..00000000000 --- a/advisories/unreviewed/2025/05/GHSA-mc2f-jgj6-6cp3/GHSA-mc2f-jgj6-6cp3.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-mc2f-jgj6-6cp3", - "modified": "2025-05-30T15:30:32Z", - "published": "2025-05-30T15:30:32Z", - "aliases": [ - "CVE-2025-3230" - ], - "details": "Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3230" - }, - { - "type": "WEB", - "url": "https://mattermost.com/security-updates" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-303" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-05-30T15:15:41Z" - } -} \ No newline at end of file