CVE-2024-48942
MEDIUMDescription
The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are valid.
Is your site exposed to CVE-2024-48942?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| syracom | secure_login |
| syracom | secure_login |
| syracom | secure_login |
References
Frequently Asked Questions
What is CVE-2024-48942? +
How severe is CVE-2024-48942? +
What products are affected by CVE-2024-48942? +
How do I check if I'm vulnerable to CVE-2024-48942? +
Related Vulnerabilities
OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the …
phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. …
Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. It allows an arbitrary …
This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API …
This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An …
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker …