Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-15150 Mattermost Fails to Lockout LDAP Users After Repeated Login Failures
Github GHSA Github GHSA GHSA-qgwx-rffp-6cx9 Mattermost Fails to Lockout LDAP Users After Repeated Login Failures
Fixes

Solution

Update Mattermost to versions 10.7.0, 10.6.2, 10.5.3, 10.4.5, 9.11.12 or higher.


Workaround

No workaround given by the vendor.

References
History

Mon, 06 Oct 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

Thu, 15 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 10:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.
Title Repeated LDAP login failures can lock an LDAP account
Weaknesses CWE-645
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-05-15T13:46:27.427Z

Reserved: 2025-04-08T11:14:14.703Z

Link: CVE-2025-31947

cve-icon Vulnrichment

Updated: 2025-05-15T13:44:49.181Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T11:15:48.270

Modified: 2025-10-06T15:30:17.227

Link: CVE-2025-31947

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T15:26:02Z