Security Advisory

CVE-2024-36250

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-11-09 17:18:34
Last updated 2024-11-12 14:52:39
Assigner Mattermost
State PUBLISHED

Description

Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds