Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
2024-11-09T18:15:14.747
2024-11-14T17:11:23.913
Analyzed
CVSSv3.1: 3.1 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_server | < 9.5.11 | Yes |
Application | mattermost | mattermost_server | < 9.11.3 | Yes |