Skip to content

x/vulndb: potential Go vuln in github.com/mattermost/mattermost-server: GHSA-fqrq-xmxj-v47x #3534

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-fqrq-xmxj-v47x references a vulnerability in the following Go modules:

Module
github.com/mattermost/mattermost-server

Description:
Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/mattermost/mattermost-server
      versions:
        - introduced: 9.11.0+incompatible
        - fixed: 9.11.9+incompatible
      vulnerable_at: 9.11.9-rc2+incompatible
summary: Mattermost Fails to Properly Perform Viewer Role Authorization in github.com/mattermost/mattermost-server
cves:
    - CVE-2025-1472
ghsas:
    - GHSA-fqrq-xmxj-v47x
references:
    - advisory: https://github.com/advisories/GHSA-fqrq-xmxj-v47x
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-1472
    - web: https://mattermost.com/security-updates
source:
    id: GHSA-fqrq-xmxj-v47x
    created: 2025-03-19T22:01:32.710511999Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions