Description
Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to escape user-controlled outputs when generating HTML pages, which allows an attacker to perform reflected cross-site scripting attacks against the users of the Mattermost server.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 8.1.0, 9.3.2, 9.4.3, 9.5.0 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27395 | Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to escape user-controlled outputs when generating HTML pages, which allows an attacker to perform reflected cross-site scripting attacks against the users of the Mattermost server. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 13 Dec 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T19:11:53.602Z
Reserved: 2024-03-14T11:40:19.218Z
Link: CVE-2024-2445
Updated: 2024-08-01T19:11:53.602Z
Status : Analyzed
Published: 2024-03-15T10:15:07.923
Modified: 2024-12-13T17:15:49.207
Link: CVE-2024-2445
No data.
OpenCVE Enrichment
No data.
EUVD