An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
mitre·CWE-521·Published 2020-06-19
Mattermost Server does not enforce rate limits on password change attempts in github.com/mattermost/mattermost-server