Mattermost-10.0/.1 advisory updates #9126
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
GHSA-q7pp-wcgr-pffx:
The issue regarding disintegration/imaging v1.6.2 where the index of the scan function in scanner.go can go out of bounds has an open PR Specific image will cause the index of the scan function in scanner.go to go out of bounds disintegration/imaging#165 but no implanted fix yet
GHSA-rhh4-rh7c-7r5v:
The affected component mholt/archiver/v3 does not yet have a fix version, upstream maintainers must implement this.
GHSA-hqqj-g6mv-rw46:
This was fixed in mattermost/server v7.4.0. In the relevant hackerone page: https://hackerone.com/reports/1685979 Mattermost staff say this is fixed and released on 10/17/22. Referencing the mattermost security updates page: https://mattermost.com/security-updates/ MMSA-2022-00118 was added on 10/14/22 and thanked the user in hackerone page for "contributing to this improvement" and the descriptions of the issue is the same between the two sources.