CVE-2024-48942
MEDIUMDescription
The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are valid.
Is your site exposed to CVE-2024-48942?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| syracom | secure_login |
| syracom | secure_login |
| syracom | secure_login |
References
Frequently Asked Questions
What is CVE-2024-48942? +
How severe is CVE-2024-48942? +
What products are affected by CVE-2024-48942? +
How do I check if I'm vulnerable to CVE-2024-48942? +
Related Vulnerabilities
This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API …
This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An …
Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. It allows an arbitrary …
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an …
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation …
Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 …