216.73.217.50

CVE-2024-36250

· Published 09/11/2024 18:15 · Modified 14/11/2024 17:11

Labels: CVE-2024-36250 2024-11-09CVE-2024-36250CWE-294CWE-303[email protected]

Essential information

Published
09/11/2024 18:15
Modified
14/11/2024 17:11
Author
Creator
CVSS
3.1 LOW (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

CVSS metrics

Description

Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mattermost / mattermost server cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
mattermost / mattermost server cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

References