mattermost-fips-10.7
Chainguard
5.3
CVSS V3
Status
Impact
This vulnerability is introduced by github.com/nwaples/rardecode@v1.1.3, a transitive dependency brought in by github.com/mholt/archiver/v3@v3.5.1 . Remediation of this vulnerability is non-trivial: remediation is only available through advancing rardecode to the new major version github.com/nwaples/rardecode/v2@v2.2.1, which upstream achieved by switching the from the archiver module to an alternate github.com/mholt/archives@v0.1.5. It is not expected that upstream will backport this change given that the product is EOL. Given the complexity, we will not backport this change
Status
Impact
Govulncheck found vulnerable symbols in Go binaries at the following locations: in mattermost-fips-10.7-10.7.4-r7.apk, at usr/bin/mattermost, usr/bin/mmctl.
Status