From 9c2d600e82d97de295041413343f041ca417e1fd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 14 Apr 2025 19:09:41 +0000 Subject: [PATCH] Publish Advisories GHSA-322v-vh2g-qvpv GHSA-322v-vh2g-qvpv --- .../GHSA-322v-vh2g-qvpv.json | 179 ++++++++++++++++++ .../GHSA-322v-vh2g-qvpv.json | 36 ---- 2 files changed, 179 insertions(+), 36 deletions(-) create mode 100644 advisories/github-reviewed/2025/04/GHSA-322v-vh2g-qvpv/GHSA-322v-vh2g-qvpv.json delete mode 100644 advisories/unreviewed/2025/04/GHSA-322v-vh2g-qvpv/GHSA-322v-vh2g-qvpv.json diff --git a/advisories/github-reviewed/2025/04/GHSA-322v-vh2g-qvpv/GHSA-322v-vh2g-qvpv.json b/advisories/github-reviewed/2025/04/GHSA-322v-vh2g-qvpv/GHSA-322v-vh2g-qvpv.json new file mode 100644 index 00000000000..7618e62fa92 --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-322v-vh2g-qvpv/GHSA-322v-vh2g-qvpv.json @@ -0,0 +1,179 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-322v-vh2g-qvpv", + "modified": "2025-04-14T19:07:44Z", + "published": "2025-04-14T09:30:24Z", + "aliases": [ + "CVE-2025-32093" + ], + "summary": "Mattermost Fails to Restrict Certain Operations on System Admins", + "details": "Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the \"Edit Other Users\" permission to perform unauthorized modifications to system administrators via improper permission validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost-server" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.5.0" + }, + { + "fixed": "10.5.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost-server" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.4.0" + }, + { + "fixed": "10.4.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost-server" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.11.0" + }, + { + "fixed": "9.11.10" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.5.0" + }, + { + "fixed": "10.5.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.4.0" + }, + { + "fixed": "10.4.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.11.0" + }, + { + "fixed": "9.11.10" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "8.0.0-20250227102013-aa4623a93199" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32093" + }, + { + "type": "WEB", + "url": "https://github.com/mattermost/mattermost/commit/aa4623a9319943d9f54383b22b55e7d06a324e20" + }, + { + "type": "PACKAGE", + "url": "https://github.com/mattermost/mattermost" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-04-14T19:07:43Z", + "nvd_published_at": "2025-04-14T07:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-322v-vh2g-qvpv/GHSA-322v-vh2g-qvpv.json b/advisories/unreviewed/2025/04/GHSA-322v-vh2g-qvpv/GHSA-322v-vh2g-qvpv.json deleted file mode 100644 index 2376d67f450..00000000000 --- a/advisories/unreviewed/2025/04/GHSA-322v-vh2g-qvpv/GHSA-322v-vh2g-qvpv.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-322v-vh2g-qvpv", - "modified": "2025-04-14T09:30:24Z", - "published": "2025-04-14T09:30:24Z", - "aliases": [ - "CVE-2025-32093" - ], - "details": "Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the \"Edit Other Users\" permission to perform unauthorized modifications to system administrators via improper permission validation.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32093" - }, - { - "type": "WEB", - "url": "https://mattermost.com/security-updates" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-863" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-04-14T07:15:14Z" - } -} \ No newline at end of file