Skip to content

Commit 6af45df

Browse files
tatianabgopherbot
authored andcommitted
data/reports: add 3 unreviewed reports
- data/reports/GO-2025-3376.yaml - data/reports/GO-2025-3377.yaml - data/reports/GO-2025-3380.yaml Fixes #3376 Fixes #3377 Fixes #3380 Change-Id: I6461a28e5a51ffbb882a38115b3b2a1fdc0d7bc5 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/641815 Auto-Submit: Tatiana Bradley <[email protected]> LUCI-TryBot-Result: Go LUCI <[email protected]> Reviewed-by: Zvonimir Pavlinovic <[email protected]>
1 parent 8da48de commit 6af45df

6 files changed

+378
-0
lines changed

data/osv/GO-2025-3376.json

+60
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3376",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2025-22149",
8+
"GHSA-675f-rq2r-jw82"
9+
],
10+
"summary": "JWK Set's HTTP client only overwrites and appends JWK to local cache during refresh in github.com/MicahParks/jwkset",
11+
"details": "JWK Set's HTTP client only overwrites and appends JWK to local cache during refresh in github.com/MicahParks/jwkset",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/MicahParks/jwkset",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0.5.0"
24+
},
25+
{
26+
"fixed": "0.6.0"
27+
}
28+
]
29+
}
30+
],
31+
"ecosystem_specific": {}
32+
}
33+
],
34+
"references": [
35+
{
36+
"type": "ADVISORY",
37+
"url": "https://github.com/MicahParks/jwkset/security/advisories/GHSA-675f-rq2r-jw82"
38+
},
39+
{
40+
"type": "ADVISORY",
41+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22149"
42+
},
43+
{
44+
"type": "FIX",
45+
"url": "https://github.com/MicahParks/jwkset/commit/01db49a90f7f20c7fb39a699a2f19a7a5f379ed3"
46+
},
47+
{
48+
"type": "FIX",
49+
"url": "https://github.com/MicahParks/jwkset/pull/41"
50+
},
51+
{
52+
"type": "REPORT",
53+
"url": "https://github.com/MicahParks/jwkset/issues/40"
54+
}
55+
],
56+
"database_specific": {
57+
"url": "https://pkg.go.dev/vuln/GO-2025-3376",
58+
"review_status": "UNREVIEWED"
59+
}
60+
}

data/osv/GO-2025-3377.json

+117
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,117 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3377",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2025-22449",
8+
"GHSA-q8fg-cp3q-5jwm"
9+
],
10+
"summary": "Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server",
11+
"details": "Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16.",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/mattermost/mattermost-server",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "9.11.0+incompatible"
24+
}
25+
]
26+
}
27+
],
28+
"ecosystem_specific": {
29+
"custom_ranges": [
30+
{
31+
"type": "ECOSYSTEM",
32+
"events": [
33+
{
34+
"introduced": "0"
35+
},
36+
{
37+
"fixed": "9.11.16"
38+
}
39+
]
40+
}
41+
]
42+
}
43+
},
44+
{
45+
"package": {
46+
"name": "github.com/mattermost/mattermost-server/v5",
47+
"ecosystem": "Go"
48+
},
49+
"ranges": [
50+
{
51+
"type": "SEMVER",
52+
"events": [
53+
{
54+
"introduced": "0"
55+
}
56+
]
57+
}
58+
],
59+
"ecosystem_specific": {}
60+
},
61+
{
62+
"package": {
63+
"name": "github.com/mattermost/mattermost-server/v6",
64+
"ecosystem": "Go"
65+
},
66+
"ranges": [
67+
{
68+
"type": "SEMVER",
69+
"events": [
70+
{
71+
"introduced": "0"
72+
}
73+
]
74+
}
75+
],
76+
"ecosystem_specific": {}
77+
},
78+
{
79+
"package": {
80+
"name": "github.com/mattermost/mattermost/server/v8",
81+
"ecosystem": "Go"
82+
},
83+
"ranges": [
84+
{
85+
"type": "SEMVER",
86+
"events": [
87+
{
88+
"introduced": "0"
89+
},
90+
{
91+
"fixed": "8.0.0-20250102081831-64c566a8280b"
92+
}
93+
]
94+
}
95+
],
96+
"ecosystem_specific": {}
97+
}
98+
],
99+
"references": [
100+
{
101+
"type": "ADVISORY",
102+
"url": "https://github.com/advisories/GHSA-q8fg-cp3q-5jwm"
103+
},
104+
{
105+
"type": "ADVISORY",
106+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22449"
107+
},
108+
{
109+
"type": "WEB",
110+
"url": "https://mattermost.com/security-updates"
111+
}
112+
],
113+
"database_specific": {
114+
"url": "https://pkg.go.dev/vuln/GO-2025-3377",
115+
"review_status": "UNREVIEWED"
116+
}
117+
}

data/osv/GO-2025-3380.json

+117
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,117 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3380",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2025-22445",
8+
"GHSA-7rgp-4j56-fm79"
9+
],
10+
"summary": "Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server",
11+
"details": "Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: .",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/mattermost/mattermost-server",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
},
25+
{
26+
"fixed": "10.3.0+incompatible"
27+
}
28+
]
29+
}
30+
],
31+
"ecosystem_specific": {
32+
"custom_ranges": [
33+
{
34+
"type": "ECOSYSTEM",
35+
"events": [
36+
{
37+
"introduced": "10.0.0"
38+
}
39+
]
40+
}
41+
]
42+
}
43+
},
44+
{
45+
"package": {
46+
"name": "github.com/mattermost/mattermost-server/v5",
47+
"ecosystem": "Go"
48+
},
49+
"ranges": [
50+
{
51+
"type": "SEMVER",
52+
"events": [
53+
{
54+
"introduced": "0"
55+
}
56+
]
57+
}
58+
],
59+
"ecosystem_specific": {}
60+
},
61+
{
62+
"package": {
63+
"name": "github.com/mattermost/mattermost-server/v6",
64+
"ecosystem": "Go"
65+
},
66+
"ranges": [
67+
{
68+
"type": "SEMVER",
69+
"events": [
70+
{
71+
"introduced": "0"
72+
}
73+
]
74+
}
75+
],
76+
"ecosystem_specific": {}
77+
},
78+
{
79+
"package": {
80+
"name": "github.com/mattermost/mattermost/server/v8",
81+
"ecosystem": "Go"
82+
},
83+
"ranges": [
84+
{
85+
"type": "SEMVER",
86+
"events": [
87+
{
88+
"introduced": "0"
89+
},
90+
{
91+
"fixed": "8.0.0-20250102081831-64c566a8280b"
92+
}
93+
]
94+
}
95+
],
96+
"ecosystem_specific": {}
97+
}
98+
],
99+
"references": [
100+
{
101+
"type": "ADVISORY",
102+
"url": "https://github.com/advisories/GHSA-7rgp-4j56-fm79"
103+
},
104+
{
105+
"type": "ADVISORY",
106+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22445"
107+
},
108+
{
109+
"type": "WEB",
110+
"url": "https://mattermost.com/security-updates"
111+
}
112+
],
113+
"database_specific": {
114+
"url": "https://pkg.go.dev/vuln/GO-2025-3380",
115+
"review_status": "UNREVIEWED"
116+
}
117+
}

data/reports/GO-2025-3376.yaml

+24
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
id: GO-2025-3376
2+
modules:
3+
- module: github.com/MicahParks/jwkset
4+
versions:
5+
- introduced: 0.5.0
6+
- fixed: 0.6.0
7+
vulnerable_at: 0.5.21
8+
summary: |-
9+
JWK Set's HTTP client only overwrites and appends JWK to local cache during
10+
refresh in github.com/MicahParks/jwkset
11+
cves:
12+
- CVE-2025-22149
13+
ghsas:
14+
- GHSA-675f-rq2r-jw82
15+
references:
16+
- advisory: https://github.com/MicahParks/jwkset/security/advisories/GHSA-675f-rq2r-jw82
17+
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-22149
18+
- fix: https://github.com/MicahParks/jwkset/commit/01db49a90f7f20c7fb39a699a2f19a7a5f379ed3
19+
- fix: https://github.com/MicahParks/jwkset/pull/41
20+
- report: https://github.com/MicahParks/jwkset/issues/40
21+
source:
22+
id: GHSA-675f-rq2r-jw82
23+
created: 2025-01-09T14:17:18.394896-05:00
24+
review_status: UNREVIEWED

data/reports/GO-2025-3377.yaml

+30
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
id: GO-2025-3377
2+
modules:
3+
- module: github.com/mattermost/mattermost-server
4+
versions:
5+
- introduced: 9.11.0+incompatible
6+
non_go_versions:
7+
- fixed: 9.11.16
8+
vulnerable_at: 10.4.1+incompatible
9+
- module: github.com/mattermost/mattermost-server/v5
10+
vulnerable_at: 5.39.3
11+
- module: github.com/mattermost/mattermost-server/v6
12+
vulnerable_at: 6.7.2
13+
- module: github.com/mattermost/mattermost/server/v8
14+
versions:
15+
- fixed: 8.0.0-20250102081831-64c566a8280b
16+
summary: Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
17+
cves:
18+
- CVE-2025-22449
19+
ghsas:
20+
- GHSA-q8fg-cp3q-5jwm
21+
references:
22+
- advisory: https://github.com/advisories/GHSA-q8fg-cp3q-5jwm
23+
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-22449
24+
- web: https://mattermost.com/security-updates
25+
notes:
26+
- fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
27+
source:
28+
id: GHSA-q8fg-cp3q-5jwm
29+
created: 2025-01-09T14:17:14.072367-05:00
30+
review_status: UNREVIEWED

data/reports/GO-2025-3380.yaml

+30
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
id: GO-2025-3380
2+
modules:
3+
- module: github.com/mattermost/mattermost-server
4+
versions:
5+
- fixed: 10.3.0+incompatible
6+
non_go_versions:
7+
- introduced: 10.0.0
8+
vulnerable_at: 10.3.0-rc4+incompatible
9+
- module: github.com/mattermost/mattermost-server/v5
10+
vulnerable_at: 5.39.3
11+
- module: github.com/mattermost/mattermost-server/v6
12+
vulnerable_at: 6.7.2
13+
- module: github.com/mattermost/mattermost/server/v8
14+
versions:
15+
- fixed: 8.0.0-20250102081831-64c566a8280b
16+
summary: Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server
17+
cves:
18+
- CVE-2025-22445
19+
ghsas:
20+
- GHSA-7rgp-4j56-fm79
21+
references:
22+
- advisory: https://github.com/advisories/GHSA-7rgp-4j56-fm79
23+
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-22445
24+
- web: https://mattermost.com/security-updates
25+
notes:
26+
- fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
27+
source:
28+
id: GHSA-7rgp-4j56-fm79
29+
created: 2025-01-09T14:16:30.962637-05:00
30+
review_status: UNREVIEWED

0 commit comments

Comments
 (0)