CVE-2024-36250

MFA Code Replay

Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds


We have discovered 17 live websites that are affected by CVE-2024-36250.

Run a Free Instant Scan




Affected Software

Product  Mattermost
Category Message Boards
Vulnerable Domains17 live websites (4.10% of Mattermost install base)
Vulnerable Versions
  • from 9.5 through 9.5.10
  • from 9.11 through 9.11.2
Vulnerable Versions Count5 versions ( 7.46% of all versions)


Common Weakness Enumeration

CWE-303 Incorrect Implementation of Authentication Algorithm



Details

  • Published - Nov 9, 2024
  • Updated - Nov 12, 2024

Credits

  • DoyenSec (finder)

Website Distribution by Country

Number of websites using CVE-2024-36250
United States9 websites



Germany2 websites
Japan2 websites
France1 websites
Iran1 websites
Korea, South1 websites
Tonga1 websites

Website Distribution by TLD

Number of websites using CVE-2024-36250
.com8 websites
.net2 websites
.at1 websites
.fr1 websites
.org1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-36250

Top websites that are affected by CVE-2024-36250. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com Iran*,***,***
******.**.kr Korea, South**,***,***
*****.****.to Japan**,***,***
**.****.net Germany**,***,***
****.***********.com United States**,***,***
**.********.com United States**,***,***
********.****.to Japan**,***,***
***.***********.com United States**,***,***
**********.*******.net United States**,***,***
****.***********.com United States**,***,***
See full domain list

FAQ

CVE-2024-36250 is Incorrect Implementation of Authentication Algorithm in Mattermost
A total of 17 websites have been identified as vulnerable to CVE-2024-36250, based on global website indexing conducted by WebTechSurvey.
The Mattermost is affected by the CVE-2024-36250 vulnerability.
Mattermost versions up to and including 9.11.2 are vulnerable to CVE-2024-36250.