MEDIUM4.3
GHSA-mj2p-v2c2-vh4v
Mattermost Incorrect Authorization vulnerability
Quick fix
GHSA-mj2p-v2c2-vh4v — github.com/mattermost/mattermost/server/v8: upgrade to the fixed version with the command below.
go get github.com/mattermost/mattermost/server/v8@v10.5.2Details
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, which allows authenticated users to view members and member information of archived channels even when this setting is disabled.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/mattermost/mattermost/server/v8
Introduced in:
10.5.0Fixed in: 10.5.2Fix
go get github.com/mattermost/mattermost/server/v8@v10.5.2Go/github.com/mattermost/mattermost/server/v8
Introduced in:
10.4.0Fixed in: 10.4.4Fix
go get github.com/mattermost/mattermost/server/v8@v10.4.4Go/github.com/mattermost/mattermost/server/v8
Introduced in:
9.11.0Fixed in: 9.11.10Fix
go get github.com/mattermost/mattermost/server/v8@v9.11.10Go/github.com/mattermost/mattermost/server/v8
Introduced in:
0Fixed in: 8.0.0-20250314142426-c049748b8863Fix
go get github.com/mattermost/mattermost/server/v8@v8.0.0-20250314142426-c049748b8863