Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-0506 Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message.
Github GHSA Github GHSA GHSA-4fp6-574p-fc35 Mattermost Jira Plugin vulnerable to Cross-Site Request Forgery
Fixes

Solution

Update Mattermost Server to versions 8.1.8 or higher. Alternatively, update the Mattermost Jira Plugin to versions v4.1.0


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-01T22:59:32.207Z

Reserved: 2024-01-30T10:23:06.712Z

Link: CVE-2024-23319

cve-icon Vulnrichment

Updated: 2024-08-01T22:59:32.207Z

cve-icon NVD

Status : Modified

Published: 2024-02-09T15:15:08.133

Modified: 2024-11-21T08:57:29.683

Link: CVE-2024-23319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.