Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-31947


Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.


Published

2025-05-15T11:15:48.270

Last Modified

2025-10-06T15:30:17.227

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-645

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost_server < 9.11.12 Yes
Application mattermost mattermost_server < 10.4.5 Yes
Application mattermost mattermost_server < 10.5.3 Yes
Application mattermost mattermost_server < 10.6.2 Yes

References