Back

MEDIUM

Bypass of "Max failed attempts" restriction via race condition

Published Dec 16, 2024

Description

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which allows an attacker to bypass of "Max failed attempts" restriction and send a big number of login attempts before being blocked via simultaneously sending multiple login requests

Affected products

Remediation

Vendor solution

Update Mattermost Server to versions 10.2.0, 10.1.3, 10.0.3, 9.11.5, 9.5.13 or higher.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Dec 16, 2024
Updated Dec 16, 2024
Reserved Dec 11, 2024
CISA Vulnrichment
Updated Dec 16, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Mattermost
Published Dec 16, 2024
Updated Dec 16, 2024
Exploited since n/a
EUVD-2024-3530 GHSA-826H-P4C3-477P