CVE-2025-54499: fallo de gravedad baja en Mattermost
Insecure string comparison enables timing attacks
Publicada el
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 3.1epss 0.3%
probabilidad de explotación
0.3%top 82% de las CVE
explotación observada
noninguna fuente lo reporta
Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to perform byte-by-byte brute force attacks via response time analysis on Cloud API keys and OAuth client secrets
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Productos afectados
Mattermost · MattermostCVEs relacionadas — Mattermost
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-25279CRITICALArbitrary file read in Mattermost Boards via import & export board archiveEPSS 24.2%CVE-2021-37859HIGHReflected XSS in OAuth FlowEPSS 3.3%CVE-2022-3257LOWServer-side Denial of Service while processing a specifically crafted GIF fileEPSS 1.3%CVE-2022-4044MEDIUMAuthenticated user could send multiple requests containing a large Auto Responder Message payload and can crash a Mattermost serverEPSS 1.1%CVE-2022-3147LOWServer-side Denial of Service while processing a specifically crafted JPEG fileEPSS 1.0%CVE-2022-1982MEDIUMA crafted SVG attachment can crash a Mattermost serverEPSS 0.9%
Referencias
https://mattermost.com/security-updates