Package
mattermost-fips-10.8
Component
github.com/nwaples/rardecode
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
This vulnerability is introduced by github.com/nwaples/rardecode@v1.1.3, a transitive dependency brought in by github.com/mholt/archiver/v3@v3.5.1 . Remediation of this vulnerability is non-trivial: remediation is only available through advancing rardecode to the new major version github.com/nwaples/rardecode/v2@v2.2.1, which upstream achieved by switching the from the archiver module to an alternate github.com/mholt/archives@v0.1.5. It is not expected that upstream will backport this change given that the product is EOL. Given the complexity, we will not backport this change
Status
Impact
Govulncheck found vulnerable symbols in Go binaries at the following locations: in mattermost-fips-10.8-10.8.4-r6.apk, at usr/bin/mattermost, usr/bin/mmctl.
Status
Impact
Govulncheck found vulnerable symbols in Go binary at usr/bin/mattermost.
Status