Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Mattermost-10.0/.1 advisory updates #9126

Merged
merged 2 commits into from
Nov 18, 2024
Merged

Conversation

jamie-albert
Copy link
Member

  1. GHSA-q7pp-wcgr-pffx:
    The issue regarding disintegration/imaging v1.6.2 where the index of the scan function in scanner.go can go out of bounds has an open PR Specific image will cause the index of the scan function in scanner.go to go out of bounds disintegration/imaging#165 but no implanted fix yet

  2. GHSA-rhh4-rh7c-7r5v:
    The affected component mholt/archiver/v3 does not yet have a fix version, upstream maintainers must implement this.

  3. GHSA-hqqj-g6mv-rw46:
    This was fixed in mattermost/server v7.4.0. In the relevant hackerone page: https://hackerone.com/reports/1685979 Mattermost staff say this is fixed and released on 10/17/22. Referencing the mattermost security updates page: https://mattermost.com/security-updates/ MMSA-2022-00118 was added on 10/14/22 and thanked the user in hackerone page for "contributing to this improvement" and the descriptions of the issue is the same between the two sources.

@jamie-albert jamie-albert requested a review from a team November 18, 2024 07:09
Copy link
Member

@debasishbsws debasishbsws left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you check if that works or not. If not we can merge this as it is.

mattermost-10.0.advisories.yaml Show resolved Hide resolved
mattermost-10.1.advisories.yaml Show resolved Hide resolved
@jamie-albert jamie-albert dismissed debasishbsws’s stale review November 18, 2024 19:46

Does not work in this implementation

@jamie-albert jamie-albert added this pull request to the merge queue Nov 18, 2024
Merged via the queue into wolfi-dev:main with commit e15b59d Nov 18, 2024
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants