Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
Moderate severity
GitHub Reviewed
Published
Apr 14, 2025
to the GitHub Advisory Database
•
Updated Apr 14, 2025
Package
Affected versions
>= 10.5.0, < 10.5.2
>= 9.11.0, < 9.11.10
< 8.0.0-20250220161544-fd356b62b4dd
Patched versions
10.5.2
9.11.10
8.0.0-20250220161544-fd356b62b4dd
Description
Published by the National Vulnerability Database
Apr 14, 2025
Published to the GitHub Advisory Database
Apr 14, 2025
Reviewed
Apr 14, 2025
Last updated
Apr 14, 2025
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.
References