Headline
GHSA-j6gg-r5jc-47cm: Mattermost fails to properly restrict access to archived channel search API
Mattermost versions < 11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the /api/v4/teams/{team_id}/channels/search_archived endpoint
Package
gomod github.com/mattermost/mattermost (Go)
Affected versions
< 5.3.2-0.20250815165020-c8d66301415d
Patched versions
5.3.2-0.20250815165020-c8d66301415d
gomod github.com/mattermost/mattermost-server (Go)
< 5.3.2-0.20250815165020-c8d66301415d
5.3.2-0.20250815165020-c8d66301415d
gomod github.com/mattermost/mattermost-server/v5 (Go)
< 5.3.2-0.20250815165020-c8d66301415d
5.3.2-0.20250815165020-c8d66301415d
gomod github.com/mattermost/mattermost-server/v6 (Go)
< 5.3.2-0.20250815165020-c8d66301415d
5.3.2-0.20250815165020-c8d66301415d
gomod github.com/mattermost/mattermost/server/v8 (Go)
< 8.0.0-20250815165020-c8d66301415d
8.0.0-20250815165020-c8d66301415d