CVE-2025-31947: Repeated LDAP login failures can lock an LDAP account
Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31947?
CVE-2025-31947 is considered a medium severity vulnerability due to its potential for unauthorized account lockouts.
How do I fix CVE-2025-31947?
To fix CVE-2025-31947, upgrade Mattermost to the latest version that addresses this issue.
What versions of Mattermost are affected by CVE-2025-31947?
Mattermost versions 10.6.1 and below, 10.5.2 and below, 10.4.4 and below, and 9.11.11 and below are affected by CVE-2025-31947.
What does CVE-2025-31947 exploit in Mattermost?
CVE-2025-31947 exploits the failure to lock out LDAP users after repeated login failures, allowing attackers to perform account lockouts.
Can CVE-2025-31947 lead to account takeovers?
CVE-2025-31947 does not directly lead to account takeovers but enables attackers to disrupt LDAP user access through lockouts.