-
Notifications
You must be signed in to change notification settings - Fork 74
Closed
Labels
excluded: EFFECTIVELY_PRIVATEThis vulnerability exists in a package can be imported, but isn't meant to be outside that module.This vulnerability exists in a package can be imported, but isn't meant to be outside that module.
Description
In GitHub Security Advisory GHSA-hv5f-73mr-7vvj, there is a vulnerability in the following Go packages or modules:
| Unit | Fixed | Vulnerable Ranges |
|---|---|---|
| github.com/mattermost/mattermost-server/v5 | 5.39 | < 5.39 |
See doc/triage.md for instructions on how to triage this report.
packages:
- package: github.com/mattermost/mattermost-server/v5
versions:
- fixed: 5.39.0
description: Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard
contents, which allows a user-assisted attacker to inject arbitrary web script
in product deployments that explicitly disable the default CSP.
published: 2021-09-23T23:11:06Z
last_modified: 2021-10-06T13:08:14Z
cves:
- CVE-2021-37860
ghsas:
- GHSA-hv5f-73mr-7vvj
links:
context:
- https://github.com/advisories/GHSA-hv5f-73mr-7vvj
Metadata
Metadata
Assignees
Labels
excluded: EFFECTIVELY_PRIVATEThis vulnerability exists in a package can be imported, but isn't meant to be outside that module.This vulnerability exists in a package can be imported, but isn't meant to be outside that module.