We’re informing you about a Mattermost security update, which addresses a high-level severity vulnerability. We highly recommend that you apply the update.
The security update is available for Mattermost dot releases 7.9.1, 7.8.2 (Extended Support Release) and 7.7.3, for both Team Edition and Enterprise Edition. They are available for download here.
Customer safety and data security are the utmost priorities for Mattermost. For our customers’ protection, and as outlined in our Responsible Disclosure policy, Mattermost does not disclose specifics on this vulnerability until 30 days after this announcement. After 30 days, we will publish specific details on the vulnerability on our Security Updates webpage.
Mattermost 7.8.2 (ESR) version also resolves the following bugs:
- Added a
exclude_files_countparameter to exclude file counts from channel stats API.
- Excluded the file count on channel stats API call on from channel header.
- Fixed an issue where the Shared Channels feature wasn’t properly included in the Professional license.
You can follow the standard upgrade instructions to apply the updates.