Mission critical collaboration security team

Mattermost security updates 10.8.1 / 10.7.3 / 10.6.6 / 10.5.6 (ESR) / 9.11.16 (ESR) released 

We’re informing you about a Mattermost security update, which addresses medium to critical severity vulnerabilities. We highly recommend that you apply the update. 

The security update is available for Mattermost dot releases 10.8.1, 10.7.3, 10.6.6, 10.5.6 (Extended Support Release), and 9.11.16 (Extended Support Release), for both Team Edition and Enterprise Edition. They are available for download here

Customer safety and data security are the utmost priorities for Mattermost. For our customers’ protection, and as outlined in our Responsible Disclosure policy, Mattermost does not disclose specifics on this vulnerability until 30 days after this announcement. After 30 days, we will publish specific details on the vulnerability on our Security Updates webpage

The v10.8.1 version also includes the following fix: 

  • Updated pre-packaged Playbooks Plugin to v2.2.0.
  • Fixed an issue where Team Admin permissions couldn’t be changed if they were missing in All Members section. See the changelog for more details. 

The v10.7.3 version also includes the following fix: 

  • Updated pre-packaged Playbooks Plugin to v2.2.0.
  • Fixed an issue where Team Admin permissions couldn’t be changed if they were missing in All Members section. See the changelog for more details. 

The v10.6.6 version also includes the following fix: 

  • Updated pre-packaged Playbooks Plugin to v2.2.0. See the changelog for more details. 

The v10.5.6 version also includes the following fix: 

  • Updated pre-packaged Playbooks Plugin to v2.2.0 and Calls Plugin to v1.7.1.
  • Fixed an issue where Team Admin permissions couldn’t be changed if they were missing in All Members section. See the changelog for more details. 

You can follow the standard upgrade instructions to apply the updates

mm

Amy Blais is the Release Manager at Mattermost, Inc. Her other roles include Community and Customer Support. She previously served as the company’s Associate Marketing Manager.