GHSA-58w6-w55x-6wq8

Suggest an improvement
Source
https://github.com/advisories/GHSA-58w6-w55x-6wq8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-58w6-w55x-6wq8/GHSA-58w6-w55x-6wq8.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-58w6-w55x-6wq8
Aliases
  • CVE-2025-13870
Published
2025-12-02T12:30:28Z
Modified
2025-12-03T16:13:04.267207Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Mattermost fails to validate user permissions in Boards
Details

Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2025-12-03T14:04:16Z",
    "nvd_published_at": "2025-12-02T10:16:01Z",
    "severity": "LOW",
    "cwe_ids": [
        "CWE-284",
        "CWE-306"
    ]
}
References

Affected packages

Go

github.com/mattermost/mattermost/server/v8

Package

Name
github.com/mattermost/mattermost/server/v8
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost/server/v8

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.0.0-20250905150616-ba86dfc5876b

github.com/mattermost/mattermost

Package

Name
github.com/mattermost/mattermost
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.11.5

github.com/mattermost/mattermost

Package

Name
github.com/mattermost/mattermost
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost

Affected ranges

Type
SEMVER
Events
Introduced
10.5.0
Fixed
10.5.13