Mattermost security updates 11.0.5, 10.12.3, and 10.11.7 (ESR) released
We’re informing you about a Mattermost security update, which addresses low to medium severity vulnerabilities. We highly recommend that you apply the update. The security update is available for Mattermost dot releases 11.0.5, 10.12.3, and 10.11.7 (Extended Support Release) for both Team Edition and Enterprise Edition. They are available for download here. You can follow the standard upgrade instructions to apply the updates.
The 11.0.5 and 10.12.3 versions also include the following fixes:
- Pre-packaged MS Teams Meetings plugin version v2.3.0.
- Pre-packaged Calls plugin version v1.11.0.
- Fixed a configuration retention issue where even active configuration got deleted.
The 11.0.5 version also includes the following fix:
- Fixed an issue where plugins could not receive 3rd-party authorization headers.
The 10.11.7 version also includes the following fixes:
- Pre-packaged Agents plugin version v1.4.0.
- Pre-packaged GitHub plugin version v2.5.0.
- Pre-packaged MS Teams Meetings plugin version v2.3.0.
- Pre-packaged Calls plugin version v1.11.0.
Additionally, we’re informing you about a Mattermost Desktop App security update, which addresses low severity vulnerabilities. We highly recommend that you apply the update. The security update is available for Mattermost Desktop App release 6.0.0. It is available for download here.
Customer safety and data security are the utmost priorities for Mattermost. For our customers’ protection, and as outlined in our Responsible Disclosure policy, Mattermost does not disclose specifics on this vulnerability until 30 days after this announcement. After 30 days, we will publish specific details on the vulnerability on our Security Updates webpage.