Description
Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 8.1.8 or higher. Alternatively, update the Mattermost Jira Plugin to versions v4.1.0
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0506 | Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message. |
Github GHSA |
GHSA-4fp6-574p-fc35 | Mattermost Jira Plugin vulnerable to Cross-Site Request Forgery |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T22:59:32.207Z
Reserved: 2024-01-30T10:23:06.712Z
Link: CVE-2024-23319
Updated: 2024-08-01T22:59:32.207Z
Status : Modified
Published: 2024-02-09T15:15:08.133
Modified: 2024-11-21T08:57:29.683
Link: CVE-2024-23319
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA