@mattermost/types@10.5.0 vulnerabilities

Shared type definitions used by the Mattermost web app

  • latest version

    11.1.0

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    1 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @mattermost/types package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Overly Restrictive Account Lockout Mechanism

    @mattermost/types is a Shared type definitions used by the Mattermost web app

    Affected versions of this package are vulnerable to Overly Restrictive Account Lockout Mechanism due to the failure in the lockout mechanism for LDAP users after multiple unsuccessful login attempts. An attacker can cause a denial of service by repeatedly attempting to log in with incorrect credentials, leading to the lockout of external LDAP accounts.

    How to fix Overly Restrictive Account Lockout Mechanism?

    Upgrade @mattermost/types to version 10.7.0 or higher.

    <10.7.0