Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-7222 Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes.
Github GHSA Github GHSA GHSA-72qv-j8vr-xvfv Mattermost Fails to Enforce MFA on Plugin Endpoints
Fixes

Solution

Update Mattermost to versions 10.6.0, 10.4.3, 10.3.4, 9.11.9, 10.5.1 or higher.


Workaround

No workaround given by the vendor.

References
History

Thu, 27 Mar 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost
Mattermost mattermost Server

Fri, 21 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Mar 2025 08:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes.
Title Bypassing MFA Enforcement on Plugin Endpoints
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-03-21T12:25:55.494Z

Reserved: 2025-03-20T08:20:28.141Z

Link: CVE-2025-25068

cve-icon Vulnrichment

Updated: 2025-03-21T12:25:50.435Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-21T09:15:12.817

Modified: 2025-03-27T14:03:38.970

Link: CVE-2025-25068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.