Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.
2025-05-15T11:15:48.270
2025-10-06T15:30:17.227
Analyzed
CVSSv3.1: 5.8 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mattermost | mattermost_server | < 9.11.12 | Yes |
| Application | mattermost | mattermost_server | < 10.4.5 | Yes |
| Application | mattermost | mattermost_server | < 10.5.3 | Yes |
| Application | mattermost | mattermost_server | < 10.6.2 | Yes |