Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mattermost_server | Mattermost | 9.5.0 (including) | 9.5.11 (excluding) |
Mattermost_server | Mattermost | 9.11.0 (including) | 9.11.3 (excluding) |