LOW2.2
GHSA-j5jw-m2ph-3jjf
Mattermost Missing Authentication for Critical Function
Quick fix
GHSA-j5jw-m2ph-3jjf — github.com/mattermost/mattermost/server/v8: upgrade to the fixed version with the command below.
go get github.com/mattermost/mattermost/server/v8@v10.5.2Details
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate MFA for other users, even if those users have not set up MFA.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/mattermost/mattermost/server/v8
Introduced in:
10.5.0Fixed in: 10.5.2Fix
go get github.com/mattermost/mattermost/server/v8@v10.5.2Go/github.com/mattermost/mattermost/server/v8
Introduced in:
9.11.0Fixed in: 9.11.10Fix
go get github.com/mattermost/mattermost/server/v8@v9.11.10Go/github.com/mattermost/mattermost/server/v8
Introduced in:
0Fixed in: 8.0.0-20250314142426-c049748b8863Fix
go get github.com/mattermost/mattermost/server/v8@v8.0.0-20250314142426-c049748b8863