CVE-2025-31947

Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.
References
Configurations

No configuration.

History

16 May 2025, 14:43

Type Values Removed Values Added
Summary
  • (es) Las versiones de Mattermost 10.6.x &lt;= 10.6.1, 10.5.x &lt;= 10.5.2, 10.4.x &lt;= 10.4.4, 9.11.x &lt;= 9.11.11 no logran bloquear a los usuarios LDAP luego de repetidos fallos de inicio de sesión, lo que permite a los atacantes bloquear cuentas LDAP externas mediante repetidos fallos de inicio de sesión a través de Mattermost.

15 May 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 11:15

Updated : 2025-05-16 14:43


NVD link : CVE-2025-31947

Mitre link : CVE-2025-31947

CVE.ORG link : CVE-2025-31947


JSON object : View

Products Affected

No product.

CWE
CWE-645

Overly Restrictive Account Lockout Mechanism