Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.
References
History

Thu, 15 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 10:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.
Title Repeated LDAP login failures can lock an LDAP account
Weaknesses CWE-645
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2025-05-15T10:41:42.104Z

Updated: 2025-05-15T13:46:27.427Z

Reserved: 2025-04-08T11:14:14.703Z

Link: CVE-2025-31947

cve-icon Vulnrichment

Updated: 2025-05-15T13:44:49.181Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-15T11:15:48.270

Modified: 2025-05-16T14:43:26.160

Link: CVE-2025-31947

cve-icon Redhat

No data.