PT-2025-16571 · Mattermost · Mattermost Server+1
Juho Forsén
·
Published
2025-04-16
·
Updated
2025-04-23
·
CVE-2025-27936
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mattermost Plugin MSTeams versions prior to 2.1.0
Mattermost Server versions 10.5.x through 10.5.1
Description
The issue allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison. This is due to the failure to perform constant time comparison on a MSTeams plugin webhook secret.
Recommendations
For Mattermost Plugin MSTeams versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue.
For Mattermost Server versions 10.5.x through 10.5.1 with the MS Teams plugin enabled, update to a version later than 10.5.1 or disable the MS Teams plugin until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost Plugin Msteams
Mattermost Server