Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.4, <= 10.4.2
- >= 10.3, <= 10.3.3
- >= 9.11, <= 9.11.8
- >= 10.5, <= 10.5.0
A vulnerability exists in Mattermost versions 10.4.x through 10.4.2, 10.3.x through 10.3.3, and 9.11.x through 9.11.8, as well as in version 10.5.0. These versions fail to properly enforce multi-factor authentication (MFA) on plugin-specific API endpoints. This oversight enables authenticated attackers to bypass MFA protections by sending requests to these vulnerable plugin routes.
Exploitation of this vulnerability allows authenticated attackers to bypass multi-factor authentication protections on plugin-specific API endpoints.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.