Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
We have discovered 17 live websites that are affected by CVE-2024-36250.
| Product | |
| Category | Message Boards |
| Vulnerable Domains | 17 live websites (4.10% of Mattermost install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 5 versions ( 7.46% of all versions) |
| 9 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 8 websites |
| .net | 2 websites |
| .at | 1 websites |
| .fr | 1 websites |
| .org | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | *,***,*** | ||
| ******.**.kr | **,***,*** | ||
| *****.****.to | **,***,*** | ||
| **.****.net | **,***,*** | ||
| ****.***********.com | **,***,*** | ||
| **.********.com | **,***,*** | ||
| ********.****.to | **,***,*** | ||
| ***.***********.com | **,***,*** | ||
| **********.*******.net | **,***,*** | ||
| ****.***********.com | **,***,*** |
FAQ