Miggo Logo

CVE-2025-31947: Mattermost Fails to Lockout LDAP Users After Repeated Login Failures

5.8

CVSS Score
3.1

Basic Information

EPSS Score
0.23863%
Published
5/15/2025
Updated
5/17/2025
KEV Status
No
Technology
TechnologyGo

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Package NameEcosystemVulnerable VersionsFirst Patched Version
github.com/mattermost/mattermost/server/v8go>= 10.6.0, <= 10.6.110.6.2
github.com/mattermost/mattermost/server/v8go>= 10.5.0, <= 10.5.210.5.3
github.com/mattermost/mattermost/server/v8go>= 10.4.0, <= 10.4.410.4.5
github.com/mattermost/mattermost/server/v8go>= 9.11.0, <= 9.11.119.11.12
github.com/mattermost/mattermost/server/v8go< 8.0.0-20250415054241-76ab3867b7858.0.0-20250415054241-76ab3867b785

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

M*tt*rmost v*rsions **.*.x <= **.*.*, **.*.x <= **.*.*, **.*.x <= **.*.*, *.**.x <= *.**.** **il to lo*kout L**P us*rs *ollowin* r*p**t** lo*in **ilur*s, w*i** *llows *tt**k*rs to lo*k *xt*rn*l L**P ***ounts t*rou** r*p**t** lo*in **ilur*s t*rou** M*

Reasoning

No *n*lysis *v*il**l*