CVE Vulnerabilities

CVE-2025-6227

Insufficiently Protected Credentials

Published: Jul 18, 2025 | Modified: Oct 14, 2025
CVSS 3.x
3.1
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Mattermost_server Mattermost 9.11.0 (including) 9.11.17 (excluding)
Mattermost_server Mattermost 10.5.0 (including) 10.5.8 (excluding)

Potential Mitigations

References