CVE-2024-48872

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which allows an attacker to bypass of "Max failed attempts" restriction and send a big number of login attempts before being blocked via simultaneously sending multiple login requests
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

15 Oct 2025, 14:13

Type Values Removed Values Added
Summary
  • (es) Las versiones 10.1.x &lt;= 10.1.2, 10.0.x &lt;= 10.0.2, 9.11.x &lt;= 9.11.4 y 9.5.x &lt;= 9.5.12 de Mattermost no pueden evitar la verificación y actualización simultánea de los intentos de inicio de sesión fallidos, lo que permite a un atacante eludir la restricción "Máximo de intentos fallidos" y enviar una gran cantidad de intentos de inicio de sesión antes de ser bloqueado mediante el envío simultáneo de múltiples solicitudes de inicio de sesión.
First Time Mattermost mattermost Server
Mattermost
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory

16 Dec 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-16 08:15

Updated : 2025-10-15 14:13


NVD link : CVE-2024-48872

Mitre link : CVE-2024-48872

CVE.ORG link : CVE-2024-48872


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')