VYPR
Moderate severityNVD Advisory· Published Apr 16, 2025· Updated Apr 16, 2025

Webhook Secret Exposure via Timing attack in MSteams plugin

CVE-2025-27936

Description

Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost/server/v8Go
>= 10.5.0, < 10.5.210.5.2
github.com/mattermost/mattermost/server/v8Go
< 8.0.0-20250314142426-c049748b88638.0.0-20250314142426-c049748b8863
github.com/mattermost/mattermost-plugin-msteamsGo
< 2.1.02.1.0

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.