Mattermost allows authenticated administrator to execute LDAP search filter injection
Moderate severity
GitHub Reviewed
Published
Jun 11, 2025
to the GitHub Advisory Database
•
Updated Jun 11, 2025
Package
Affected versions
>= 10.7.0, < 10.7.2
>= 10.6.0, < 10.6.4
>= 10.5.0, < 10.5.5
>= 9.11.0, < 9.11.14
Patched versions
10.7.2
10.6.4
10.5.5
9.11.14
< 8.0.0-20250414112942-77892234944b
8.0.0-20250414112942-77892234944b
Description
Published by the National Vulnerability Database
Jun 11, 2025
Published to the GitHub Advisory Database
Jun 11, 2025
Reviewed
Jun 11, 2025
Last updated
Jun 11, 2025
Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LDAP group ID attributes, allowing an authenticated administrator with PermissionSysconsoleWriteUserManagementGroups permission to execute LDAP search filter injection via the PUT /api/v4/ldap/groups/{remote_id}/link API when objectGUID is configured as the Group ID Attribute.
References