Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mattermost_server | Mattermost | 9.5.0 (including) | 9.5.11 (excluding) |
Mattermost_server | Mattermost | 9.11.0 (including) | 9.11.3 (excluding) |