PT-2024-26932 · Mattermost · Mattermost

Doyensec

·

Published

2024-11-09

·

Updated

2024-11-15

·

CVE-2024-36250

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.11.x through 9.11.2 Mattermost versions 9.5.x through 9.5.10
Description The issue allows an attacker to reuse the MFA code within ~30 seconds due to a failure to protect the MFA code against replay attacks.
Recommendations For versions 9.11.x through 9.11.2, update to a version later than 9.11.2 to resolve the issue. For versions 9.5.x through 9.5.10, update to a version later than 9.5.10 to resolve the issue. As a temporary workaround, consider restricting access to MFA-protected resources until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-36250
CVE-2024-36250

Affected Products

Mattermost