Collaborative intelligence team​

Mattermost security updates 11.4.1, 11.3.2, 11.2.4, and 10.11.12 (ESR) released

We’re informing you about a Mattermost security update, which addresses low to high severity vulnerabilities. We highly recommend that you apply the update. The security update is available for Mattermost dot releases 11.4.1, 11.3.2, 11.2.4, and 10.11.12 (Extended Support Release) for both Team Edition and Enterprise Edition. They are available for download here. You can follow the standard upgrade instructions to apply the updates.

The 11.4.1, 11.3.2, and 11.2.4 versions also include the following fixes: 

  •  Pre-packaged Zoom plugin version v1.12.0.
  •  Fixed an issue with link preview metadata processing and image validation.
  •  Fixed an issue where rate limiting was missing from the login endpoint (5 requests/second, 10 burst).

The 10.11.12 version also includes the following fixes: 

  •  Pre-packaged Zoom plugin version v1.12.0.
  •  Pre-packaged Playbooks plugin version v2.4.3.
  •  Fixed an issue with link preview metadata processing and image validation.
  •  Fixed an issue where rate limiting was missing from the login endpoint (5 requests/second, 10 burst).

Additionally, we’re informing you about a Mattermost Mobile App security update, which addresses a medium severity vulnerability. We highly recommend that you apply the update. The security update is available for Mattermost Mobile App release 2.37.1. It is available for download here

Customer safety and data security are the utmost priorities for Mattermost. For our customers’ protection, and as outlined in our Responsible Disclosure policy, Mattermost does not disclose specifics on this vulnerability until 30 days after this announcement. After 30 days, we will publish specific details on the vulnerability on our Security Updates webpage

mm

Amy Blais is the Release Manager at Mattermost, Inc. Her other roles include Community and Customer Support. She previously served as the company’s Associate Marketing Manager.