Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- <= 10.4.2
- <= 10.3.3
- <= 9.11.8
A vulnerability exists in Mattermost versions 10.4.x through 10.4.2, 10.3.x through 10.3.3, and 9.11.x through 9.11.8, where multi-factor authentication (MFA) is not properly enforced on certain search APIs. This flaw enables authenticated attackers to bypass MFA protections by exploiting user search, channel search, or team search queries.
Exploitation of this vulnerability allows authenticated attackers to bypass multi-factor authentication protections on specific search APIs, potentially leading to unauthorized access or actions that require MFA.
Users can upgrade to Mattermost versions 10.9.0, 10.8.0, 10.7.0, 10.6.0, or 9.11.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.