Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost Plugin MSTeams to version 2.1.1 or Mattermost Server to versions 10.6.0, 10.5.2 or higher.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11359 | Mattermost vulnerable to Observable Timing Discrepancy |
Github GHSA |
GHSA-2j87-p623-8cc2 | Mattermost vulnerable to Observable Timing Discrepancy |
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Wed, 14 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server Mattermost ms Teams |
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:ms_teams:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mattermost
Mattermost mattermost Server Mattermost ms Teams |
Wed, 16 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Apr 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison. | |
| Title | Webhook Secret Exposure via Timing attack in MSteams plugin | |
| Weaknesses | CWE-208 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-04-16T14:32:45.176Z
Reserved: 2025-04-08T11:14:14.689Z
Link: CVE-2025-27936
Updated: 2025-04-16T14:22:49.604Z
Status : Analyzed
Published: 2025-04-16T10:15:14.797
Modified: 2026-01-14T14:29:28.477
Link: CVE-2025-27936
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA