
Mattermost security updates 10.7.2 / 10.6.4 / 10.5.5 (ESR) / 9.11.15 (ESR) released
We’re informing you about a Mattermost security update, which addresses low to medium severity vulnerabilities. We highly recommend that you apply the update.
The security update is available for Mattermost dot releases 10.7.2, 10.6.4, 10.5.5 (Extended Support Release), and 9.11.15 (Extended Support Release), for both Team Edition and Enterprise Edition. They are available for download here.
Customer safety and data security are the utmost priorities for Mattermost. For our customers’ protection, and as outlined in our Responsible Disclosure policy, Mattermost does not disclose specifics on this vulnerability until 30 days after this announcement. After 30 days, we will publish specific details on the vulnerability on our Security Updates webpage.
The v9.11.15 version also includes the following fixes:
- Brought back the bug fix for MM-61361, since the performance regression has been fixed by tweaking the offending SQL query.
- A new index to the CategoryId column in SidebarChannels table was added to improve query performance. See the changelog for more details.
The v10.5.5 version also includes the following fix:
- A new index to the CategoryId column in SidebarChannels table was added to improve query performance. See the changelog for more details.
You can follow the standard upgrade instructions to apply the updates.