GHSA-32rp-q37p-jg6w

Suggest an improvement
Source
https://github.com/advisories/GHSA-32rp-q37p-jg6w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-32rp-q37p-jg6w/GHSA-32rp-q37p-jg6w.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-32rp-q37p-jg6w
Aliases
Published
2022-04-20T00:00:30Z
Modified
2024-08-21T15:27:18.428647Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Insecure plugin handling in Mattermost
Details

Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known vulnerabilities.

Database specific
{
    "nvd_published_at": "2022-04-19T21:15:00Z",
    "cwe_ids": [
        "CWE-862"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2022-04-28T21:12:15Z"
}
References

Affected packages

Go / github.com/mattermost/mattermost-server/v6

Package

Name
github.com/mattermost/mattermost-server/v6
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost-server/v6

Affected ranges

Type
SEMVER
Events
Introduced
6.4.0
Fixed
6.5.0