CVE-2024-48872

Bypass of "Max failed attempts" restriction via race condition

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which allows an attacker to bypass of "Max failed attempts" restriction and send a big number of login attempts before being blocked via simultaneously sending multiple login requests


We have discovered 32 live websites that are affected by CVE-2024-48872.

Run a Free Instant Scan




Affected Software

Product  Mattermost
Category Message Boards
Vulnerable Domains32 live websites (8.00% of Mattermost install base)
Vulnerable Versions
  • from 9.5 through 9.5.12
  • from 9.11 through 9.11.4
  • from 10 through 10.0.2
  • from 10.1 through 10.1.2
Vulnerable Versions Count9 versions ( 13% of all versions)


Common Weakness Enumeration

CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')



Details

  • Published - Dec 16, 2024
  • Updated - Dec 16, 2024

Credits

  • Roman Shchekin (qtros) (finder)

Website Distribution by Country

Number of websites using CVE-2024-48872
United States12 websites



Germany6 websites
France4 websites
Japan2 websites
Canada1 websites
Greece1 websites
Iran1 websites
Italy1 websites
Netherlands1 websites
Russia1 websites

Website Distribution by TLD

Number of websites using CVE-2024-48872
.com9 websites
.net4 websites
.org3 websites
.de2 websites
.at1 websites
.dk1 websites
.fr1 websites
.info1 websites
.pl1 websites
.ru1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-48872

Top websites that are affected by CVE-2024-48872. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.**************.org Germany*,***,***
****.******.com United States*,***,***
*********.com Iran*,***,***
*****.****.to Japan**,***,***
**.****.net Germany**,***,***
****.***********.com United States**,***,***
**********.******.***.gr Greece**,***,***
******.****.info Germany**,***,***
**.********.com United States**,***,***
******.pl France**,***,***
See full domain list

FAQ

CVE-2024-48872 is Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in Mattermost
A total of 32 websites have been identified as vulnerable to CVE-2024-48872, based on global website indexing conducted by WebTechSurvey.
The Mattermost is affected by the CVE-2024-48872 vulnerability.
Mattermost versions up to and including 10.1.2 are vulnerable to CVE-2024-48872.