Description
Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message.
Published: 2024-02-09
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update Mattermost Server to versions 8.1.8 or higher. Alternatively, update the Mattermost Jira Plugin to versions v4.1.0

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-0506 Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message.
Github GHSA Github GHSA GHSA-4fp6-574p-fc35 Mattermost Jira Plugin vulnerable to Cross-Site Request Forgery
References
History

No history.

Subscriptions

Mattermost Mattermost Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-01T22:59:32.207Z

Reserved: 2024-01-30T10:23:06.712Z

Link: CVE-2024-23319

cve-icon Vulnrichment

Updated: 2024-08-01T22:59:32.207Z

cve-icon NVD

Status : Modified

Published: 2024-02-09T15:15:08.133

Modified: 2024-11-21T08:57:29.683

Link: CVE-2024-23319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses