Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which allows an attacker to bypass of "Max failed attempts" restriction and send a big number of login attempts before being blocked via simultaneously sending multiple login requests
We have discovered 32 live websites that are affected by CVE-2024-48872.
| Product | |
| Category | Message Boards |
| Vulnerable Domains | 32 live websites (8.00% of Mattermost install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 9 versions ( 13% of all versions) |
| 12 websites | |
| 6 websites | |
| 4 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 9 websites |
| .net | 4 websites |
| .org | 3 websites |
| .de | 2 websites |
| .at | 1 websites |
| .dk | 1 websites |
| .fr | 1 websites |
| .info | 1 websites |
| .pl | 1 websites |
| .ru | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.**************.org | *,***,*** | ||
| ****.******.com | *,***,*** | ||
| *********.com | *,***,*** | ||
| *****.****.to | **,***,*** | ||
| **.****.net | **,***,*** | ||
| ****.***********.com | **,***,*** | ||
| **********.******.***.gr | **,***,*** | ||
| ******.****.info | **,***,*** | ||
| **.********.com | **,***,*** | ||
| ******.pl | **,***,*** |
FAQ