LDAP User Authentication Vulnerability in Mattermost by Mattermost
CVE-2025-31947
5.8MEDIUM
What is CVE-2025-31947?
Certain versions of Mattermost are vulnerable due to their failure to lock out external LDAP user accounts after multiple failed login attempts. This loophole allows malicious actors to exploit this feature, potentially gaining unauthorized access by triggering repeated login failures against LDAP accounts. Such vulnerabilities can lead to unauthorized access breaches, posing a significant risk to sensitive information within the Mattermost platform.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mattermost 10.6.0 <= 10.6.1
Mattermost 10.5.0 <= 10.5.2
Mattermost 10.4.0 <= 10.4.4
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
John Landells