PT-2025-16571 · Mattermost · Mattermost Server+1

Juho Forsén

·

Published

2025-04-16

·

Updated

2025-04-23

·

CVE-2025-27936

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost Plugin MSTeams versions prior to 2.1.0 Mattermost Server versions 10.5.x through 10.5.1
Description The issue allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison. This is due to the failure to perform constant time comparison on a MSTeams plugin webhook secret.
Recommendations For Mattermost Plugin MSTeams versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue. For Mattermost Server versions 10.5.x through 10.5.1 with the MS Teams plugin enabled, update to a version later than 10.5.1 or disable the MS Teams plugin until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-27936
GHSA-2J87-P623-8CC2
GO-2025-3618
OPENSUSE-SU-2025:15017-1

Affected Products

Mattermost Plugin Msteams
Mattermost Server