Vulnerabilities > Mattermost > Mattermost Server > 9.5.10

DATE CVE VULNERABILITY TITLE RISK
2024-11-09 CVE-2024-36250 Authentication Bypass by Capture-replay vulnerability in Mattermost Server
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
network
high complexity
mattermost CWE-294
4.8