5.3
CVSS V3
Status
Justification
Impact
This vulnerability was fixed in mattermost v10.3.0, and is not present in v10.3.1 or later. The componentVersion is being flagged incorrectly here by some scanners. A bug has been filed upstream against Syft, and the maintainers have confirmed it's a scanner issue:
Status