Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the subscription resulting in registered users on Jira being able to create webhooks that give them access to all Jira issues.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0701 | Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the subscription resulting in registered users on Jira being able to create webhooks that give them access to all Jira issues. |
Github GHSA |
GHSA-qr8f-cjw7-838m | Mattermost Jira Plugin does not properly check security levels |
Fixes
Solution
Update Mattermost Server to versions 8.1.8 or higher. Alternatively, update the Mattermost Jira Plugin to version 4.0.1 or higher.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-21T15:26:06.746Z
Reserved: 2024-01-30T10:23:06.701Z
Link: CVE-2024-24774
Updated: 2024-08-01T23:28:12.325Z
Status : Modified
Published: 2024-02-09T15:15:08.343
Modified: 2024-11-21T08:59:40.547
Link: CVE-2024-24774
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA