Mattermost Server 9.11.x < 9.11.13 / 10.5.x < 10.5.4 / 10.6.x < 10.6.3 / 10.7.1 Multiple Vulnerabilities (MMSA-2025-00458, MMSA-2025-00463, MMSA-2025-00467)

The version of Mattermost Server installed on the remote host is prior to 9.11.13, 10.5.4, 10.6.3, or 10.7.0. It is, therefore, affected by multiple vulnerabilities as referenced in the MMSA-2025-0045 ...

Continue Reading
RHEL 10 : mod_auth_openidc (RHSA-2025:7490)

The remote Redhat Enterprise Linux 10 host has a package installed that is affected by a vulnerability as referenced in the RHSA-2025:7490 advisory. The mod_auth_openidc is an OpenID Connect authentic ...

Continue Reading
Addressing API Security with NIST SP 800-228

According to the Wallarm Q1 2025 ThreatStats report, 70% of all application attacks target APIs. The industry can no longer treat API security as a sidenote; it’s time to treat it as the main event. ...

Continue Reading
Improper Authentication

Mattermost is vulnerable to Improper Authentication. The vulnerability is due to insecure OAuth credential handling due to failure to clear Google OAuth credentials when converting user accounts to bo ...

Continue Reading
Scattered Spider: Understanding Help Desk Scams and How to Defend Your Organization

In the wake of high-profile attacks on UK retailers Marks &amp; Spencer and Co-op, Scattered Spider has been all over the media, with coverage spilling over into the mainstream news due to the sev ...

Continue Reading
RHEL 9 : mod_auth_openidc (RHSA-2025:7419)

The remote Redhat Enterprise Linux 9 host has a package installed that is affected by a vulnerability as referenced in the RHSA-2025:7419 advisory. The mod_auth_openidc is an OpenID Connect authentica ...

Continue Reading
FreeBSD : glpi-project — GLPI multiple vulnerabilities (c36decbe-3c84-11f0-8d29-b42e991fc52e)

The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the c36decbe-3c84-11f0-8d29-b42e991fc52e advisor ...

Continue Reading
CVE-2025-2571

Mattermost versions 10.7.x &lt;= 10.7.0, 10.6.x &lt;= 10.6.2, 10.5.x &lt;= 10.5.3, 9.11.x &lt;= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot acco ...

Continue Reading

Back to Main

Subscribe for the latest news: