cbcvebase.
CVE-2024-36250
published 2024-11-09

CVE-2024-36250: Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code…

PriorityP423medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
0.21%
11.1th percentile
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds

Affected

4 ranges
VendorProductVersion rangeFixed in
mattermostmattermost9.11.0 – 9.11.2
mattermostmattermost9.5.0 – 9.5.10
mattermostmattermost_server>= 9.11.0 < 9.11.39.11.3
mattermostmattermost_server>= 9.5.0 < 9.5.119.5.11
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.