CVE-2024-48942

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Oct 10, 2024
Updated: Oct 11, 2024
CWE ID 799

Summary

CVE-2024-48942 is a vulnerability affecting the Syracom Secure Login (2FA) plugin used in Jira, Confluence, and Bitbucket. This issue permits remote attackers to attempt brute-force attacks on the 2FA PIN through the plugins/servlet/twofactor/public/pinvalidation endpoint. The vulnerability allows the last 30 and the next 30 tokens to be valid, increasing the likelihood of a successful attack. This weakness poses a significant risk to organizations using these Atlassian products and could lead to unauthorized access to sensitive data. Upgrading to a patched version of the plugin is strongly recommended to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share