CVE-2024-48942
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2024-48942 is a vulnerability affecting the Syracom Secure Login (2FA) plugin used in Jira, Confluence, and Bitbucket. This issue permits remote attackers to attempt brute-force attacks on the 2FA PIN through the plugins/servlet/twofactor/public/pinvalidation endpoint. The vulnerability allows the last 30 and the next 30 tokens to be valid, increasing the likelihood of a successful attack. This weakness poses a significant risk to organizations using these Atlassian products and could lead to unauthorized access to sensitive data. Upgrading to a patched version of the plugin is strongly recommended to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Syracom Secure Login