VDB
Sign up
MEDIUM4.3

GHSA-mj2p-v2c2-vh4v

Mattermost Incorrect Authorization vulnerability

Quick fix

GHSA-mj2p-v2c2-vh4v — github.com/mattermost/mattermost/server/v8: upgrade to the fixed version with the command below.

go get github.com/mattermost/mattermost/server/v8@v10.5.2

Details

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, which allows authenticated users to view members and member information of archived channels even when this setting is disabled.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/mattermost/mattermost/server/v8
Introduced in: 10.5.0Fixed in: 10.5.2
Fixgo get github.com/mattermost/mattermost/server/v8@v10.5.2
Go/github.com/mattermost/mattermost/server/v8
Introduced in: 10.4.0Fixed in: 10.4.4
Fixgo get github.com/mattermost/mattermost/server/v8@v10.4.4
Go/github.com/mattermost/mattermost/server/v8
Introduced in: 9.11.0Fixed in: 9.11.10
Fixgo get github.com/mattermost/mattermost/server/v8@v9.11.10
Go/github.com/mattermost/mattermost/server/v8
Introduced in: 0Fixed in: 8.0.0-20250314142426-c049748b8863
Fixgo get github.com/mattermost/mattermost/server/v8@v8.0.0-20250314142426-c049748b8863

References