Description
Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the subscription resulting in registered users on Jira being able to create webhooks that give them access to all Jira issues.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 8.1.8 or higher. Alternatively, update the Mattermost Jira Plugin to version 4.0.1 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0701 | Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the subscription resulting in registered users on Jira being able to create webhooks that give them access to all Jira issues. |
Github GHSA |
GHSA-qr8f-cjw7-838m | Mattermost Jira Plugin does not properly check security levels |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-21T15:26:06.746Z
Reserved: 2024-01-30T10:23:06.701Z
Link: CVE-2024-24774
Updated: 2024-08-01T23:28:12.325Z
Status : Modified
Published: 2024-02-09T15:15:08.343
Modified: 2024-11-21T08:59:40.547
Link: CVE-2024-24774
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA