CVE-2024-36250

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Nov 9, 2024
Updated: Nov 14, 2024
CWE ID 294
CWE ID 303

Summary

CVE-2024-36250 is a vulnerability affecting Mattermost versions 9.11.x up to 9.11.2, and 9.5.x up to 9.5.10. This issue permits attackers to reuse Multi-Factor Authentication (MFA) codes within approximately 30 seconds, bypassing the protection against replay attacks. Successful exploitation grants unauthorized access to user accounts. Users are encouraged to update their Mattermost instances to the latest versions to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mattermost Server

Affected Vendors

  • Mattermost, Inc.