-
Notifications
You must be signed in to change notification settings - Fork 74
Closed
Labels
excluded: EFFECTIVELY_PRIVATEThis vulnerability exists in a package can be imported, but isn't meant to be outside that module.This vulnerability exists in a package can be imported, but isn't meant to be outside that module.
Description
In GitHub Security Advisory GHSA-5jph-wrq7-v9hf, there is a vulnerability in the following Go packages or modules:
| Unit | Fixed | Vulnerable Ranges |
|---|---|---|
| github.com/mattermost/mattermost-server | 7.3.1 | >= 7.3.0, < 7.3.1 |
See doc/triage.md for instructions on how to triage this report.
modules:
- module: TODO
versions:
- introduced: 7.3.0
fixed: 7.3.1
packages:
- package: github.com/mattermost/mattermost-server
- module: TODO
versions:
- introduced: 7.2.0
fixed: 7.2.1
packages:
- package: github.com/mattermost/mattermost-server
- module: TODO
versions:
- fixed: 7.1.4
packages:
- package: github.com/mattermost/mattermost-server
description: A denial-of-service vulnerability in Mattermost allows an authenticated
user to crash the server via multiple large autoresponder messages.
cves:
- CVE-2022-4044
ghsas:
- GHSA-5jph-wrq7-v9hf
Metadata
Metadata
Assignees
Labels
excluded: EFFECTIVELY_PRIVATEThis vulnerability exists in a package can be imported, but isn't meant to be outside that module.This vulnerability exists in a package can be imported, but isn't meant to be outside that module.