DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CGA-hw9f-q7h4-w2jg

Published

Last updated

https://images.chainguard.dev/security/CGA-hw9f-q7h4-w2jg
Package

mattermost-fips-10.7

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2025-11579
  • GHSA-rwvp-r38j-9rgg

Severity

5.3

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-11579

Updates

Status

Fix not planned

Impact

This vulnerability is introduced by github.com/nwaples/rardecode@v1.1.3, a transitive dependency brought in by github.com/mholt/archiver/v3@v3.5.1 . Remediation of this vulnerability is non-trivial: remediation is only available through advancing rardecode to the new major version github.com/nwaples/rardecode/v2@v2.2.1, which upstream achieved by switching the from the archiver module to an alternate github.com/mholt/archives@v0.1.5. It is not expected that upstream will backport this change given that the product is EOL. Given the complexity, we will not backport this change

Status

Affected

Impact

Govulncheck found vulnerable symbols in Go binaries at the following locations: in mattermost-fips-10.7-10.7.4-r7.apk, at usr/bin/mattermost, usr/bin/mmctl.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing