Mattermost Platform

Mattermost security update 5.37.1 (Extended Support Release), 5.36.2, 5.35.5, 5.31.9 (Extended Support Release)

We’re informing you about a Mattermost security update, which addresses a medium-level severity vulnerability that was discovered during a security research review by Adrian (ThiefMaster). We highly recommend that you apply the update.

The security update is available for Mattermost dot releases 5.37.1 (ESR), 5.36.2, 5.35.5, and 5.31.9 (ESR) for both Team Edition and Enterprise Edition. They are available for download here.

Customer safety and data security are the utmost priorities for Mattermost. For our customers’ protection, and as outlined in our Responsible Disclosure policy, Mattermost does not disclose specifics on this vulnerability until 30 days after this announcement. After 30 days, we will publish specific details on the vulnerability on our Security Updates webpage.

Mattermost v5.37.1 (ESR) also resolves the following bugs:

  • Improved typing performance in affected environments by reducing the frequency at which drafts are saved.
  • Fixed an issue in clustering where a mutex would fail to be unlocked when a timeout happened.

Mattermost v5.31.9 (ESR) also resolves the following bug:

  • Improved typing performance in affected environments by reducing the frequency at which drafts are saved.

You can follow the standard upgrade instructions to apply the updates.

mm

Amy Blais is the Release Manager at Mattermost, Inc. Her other roles include Community and Customer Support. She previously served as the company’s Associate Marketing Manager.