Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/mattermost/mattermost-server(Go) | 0 | 11.1.0 | N/A |
| github.com/mattermost/mattermost/server/v8(Go) | 0 | 8.0.0-20250912063506-7d8b7b5e4a60 | N/A |
CVSS Metrics